Aggregator
Submit #410994: kalvinGit kvf-admin 2021-09-09 Unrestricted Upload [Accepted]
1 year 6 months ago
Submit #410994 / VDB-278662
Arvin
CVE-2024-9278 | HuankeMao SCRM up to 0.0.3 Administrator Backend WxkConfig.php upload_domain_verification_file unrestricted upload
1 year 6 months ago
A vulnerability, which was classified as critical, has been found in HuankeMao SCRM up to 0.0.3. Affected by this issue is the function upload_domain_verification_file of the file WxkConfig.php of the component Administrator Backend. The manipulation of the argument domain_verification_file leads to unrestricted upload.
This vulnerability is handled as CVE-2024-9278. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #411118: funnyzpc Mee-Admin 1.6 Stored XSS [Accepted]
1 year 6 months ago
Submit #411118 / VDB-278661
Armny
CVE-2024-9277 | Langflow up to 1.0.18 HTTP POST Request utils.py remaining_text redos
1 year 6 months ago
A vulnerability classified as problematic was found in Langflow up to 1.0.18. Affected by this vulnerability is an unknown functionality of the file \src\backend\base\langflow\interface\utils.py of the component HTTP POST Request Handler. The manipulation of the argument remaining_text leads to inefficient regular expression complexity.
This vulnerability is known as CVE-2024-9277. The attack needs to be done within the local network. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
Submit #410393: Huankemao SCRM 0.0.3 Unrestricted Upload [Accepted]
1 year 6 months ago
Submit #410393 / VDB-278660
wiki
Submit #410043: langflow-ai langflow <=v1.0.18 Redos [Accepted]
1 year 6 months ago
Submit #410043 / VDB-278659
HRP_0
CVE-2024-9276 | TMsoft MyAuth Gateway 3 /index.php console/nocache/cmd cross site scripting
1 year 6 months ago
A vulnerability classified as problematic has been found in TMsoft MyAuth Gateway 3. Affected is an unknown function of the file /index.php. The manipulation of the argument console/nocache/cmd leads to cross site scripting.
This vulnerability is traded as CVE-2024-9276. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2024-9275 | jeanmarc77 123solar up to 1.8.4.5 /admin/admin_invt2.php PROTOCOLx file inclusion (Issue 75)
1 year 6 months ago
A vulnerability was found in jeanmarc77 123solar up to 1.8.4.5. It has been rated as critical. This issue affects some unknown processing of the file /admin/admin_invt2.php. The manipulation of the argument PROTOCOLx leads to file inclusion.
The identification of this vulnerability is CVE-2024-9275. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #409126: TMsoft MyAuth Gateway 3 Injection [Accepted]
1 year 6 months ago
Submit #409126 / VDB-278658
The_Druk
CVE-2024-7149 | Event Manager, Events Calendar, Tickets, Registrations Plugin file inclusion
1 year 6 months ago
A vulnerability was found in Event Manager, Events Calendar, Tickets, Registrations Plugin up to 4.0.8 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to file inclusion.
This vulnerability was named CVE-2024-7149. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2024-9245 | Foxit PDF Reader Update Service permission (ZDI-24-1297)
1 year 6 months ago
A vulnerability was found in Foxit PDF Reader. It has been classified as critical. This affects an unknown part of the component Update Service. The manipulation leads to permission issues.
This vulnerability is uniquely identified as CVE-2024-9245. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-9244 | Foxit PDF Reader Update Service permission (ZDI-24-1298)
1 year 6 months ago
A vulnerability was found in Foxit PDF Reader and classified as critical. Affected by this issue is some unknown functionality of the component Update Service. The manipulation leads to permission issues.
This vulnerability is handled as CVE-2024-9244. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Submit #408326: 123Solar 1.8.4.5 File Inclusion [Accepted]
1 year 6 months ago
Submit #408326 / VDB-278657
hejiasheng
CVE-2024-9257 | Logsign Unified SecOps Platform delete_gsuite_key_file denial of service (ZDI-24-1295)
1 year 6 months ago
A vulnerability has been found in Logsign Unified SecOps Platform and classified as problematic. Affected by this vulnerability is the function delete_gsuite_key_file. The manipulation leads to denial of service.
This vulnerability is known as CVE-2024-9257. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-9246 | Foxit PDF Reader Annotation out-of-bounds (ZDI-24-1299)
1 year 6 months ago
A vulnerability, which was classified as problematic, was found in Foxit PDF Reader. Affected is an unknown function of the component Annotation. The manipulation leads to out-of-bounds read.
This vulnerability is traded as CVE-2024-9246. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-9252 | Foxit PDF Reader AcroForm use after free (ZDI-24-1304)
1 year 6 months ago
A vulnerability, which was classified as problematic, has been found in Foxit PDF Reader. This issue affects some unknown processing of the component AcroForm. The manipulation leads to use after free.
The identification of this vulnerability is CVE-2024-9252. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-9253 | Foxit PDF Reader AcroForm out-of-bounds (ZDI-24-1305)
1 year 6 months ago
A vulnerability classified as problematic was found in Foxit PDF Reader. This vulnerability affects unknown code of the component AcroForm. The manipulation leads to out-of-bounds read.
This vulnerability was named CVE-2024-9253. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-9251 | Foxit PDF Reader Annotation use after free (ZDI-24-1306)
1 year 6 months ago
A vulnerability classified as problematic has been found in Foxit PDF Reader. This affects an unknown part of the component Annotation. The manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2024-9251. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-9256 | Foxit PDF Reader AcroForm out-of-bounds (ZDI-24-1309)
1 year 6 months ago
A vulnerability was found in Foxit PDF Reader. It has been rated as problematic. Affected by this issue is some unknown functionality of the component AcroForm. The manipulation leads to out-of-bounds read.
This vulnerability is handled as CVE-2024-9256. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com