Aggregator
CVE-2024-7094 | JS Help Desk Plugin up to 2.8.6 on WordPress code injection
1 year 7 months ago
A vulnerability was found in JS Help Desk Plugin up to 2.8.6 on WordPress and classified as critical. This issue affects some unknown processing. The manipulation leads to code injection.
The identification of this vulnerability is CVE-2024-7094. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-42482 | fish-shop syntax-check up to 1.6.11 Workflow delimiters
1 year 7 months ago
A vulnerability has been found in fish-shop syntax-check up to 1.6.11 and classified as problematic. This vulnerability affects unknown code of the component Workflow Handler. The manipulation leads to improper neutralization of delimiters.
This vulnerability was named CVE-2024-42482. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
SecWiki News 2024-08-12 Review
1 year 7 months ago
ET-BERT:用于加密流量分类的带有预训练Transformer的上下文数据报表征 by ourren
在Docker上部署Ollama+AnythingLLM完成本地LLM Agent部署 by 洞源实验室
更多最新文章,请访问SecWiki
在Docker上部署Ollama+AnythingLLM完成本地LLM Agent部署 by 洞源实验室
更多最新文章,请访问SecWiki
CVE-2024-42632 | FrogCMS 0.9.5 /admin/ cross-site request forgery
1 year 7 months ago
A vulnerability, which was classified as problematic, was found in FrogCMS 0.9.5. This affects an unknown part of the file /admin/?/page/add. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2024-42632. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-39091 | MIPC Camera prior 5.4.1.240424171021 ccm_debug os command injection
1 year 7 months ago
A vulnerability, which was classified as critical, has been found in MIPC Camera. Affected by this issue is some unknown functionality of the component ccm_debug. The manipulation leads to os command injection.
This vulnerability is handled as CVE-2024-39091. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-42480 | clastix kamaji prior 24.8.2 TCP API Server access control
1 year 7 months ago
A vulnerability classified as critical was found in clastix kamaji. Affected by this vulnerability is an unknown functionality of the component TCP API Server Handler. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2024-42480. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-42481 | skyportlabs skyportd up to 0.2.1 resource consumption
1 year 7 months ago
A vulnerability classified as critical has been found in skyportlabs skyportd up to 0.2.1. Affected is an unknown function. The manipulation leads to resource consumption.
This vulnerability is traded as CVE-2024-42481. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-42485 | pxlrbt filament-excel up to 2.3.2 /filament-excel/{path} path traversal
1 year 7 months ago
A vulnerability was found in pxlrbt filament-excel up to 2.3.2. It has been rated as critical. This issue affects some unknown processing of the file /filament-excel/{path}. The manipulation leads to path traversal.
The identification of this vulnerability is CVE-2024-42485. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-36877 | Micro-Star International Z590/Z490/Z790/B760/B560/B660/B460 SMI write-what-where condition
1 year 7 months ago
A vulnerability was found in Micro-Star International Z590, Z490, Z790, B760, B560, B660 and B460. It has been declared as critical. This vulnerability affects unknown code of the component SMI Handler. The manipulation leads to write-what-where condition.
This vulnerability was named CVE-2024-36877. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2024-42479 | ggerganov llama.cpp b3427 rpc_tensor write-what-where condition (GHSA-wcr5-566p-9cwj)
1 year 7 months ago
A vulnerability was found in ggerganov llama.cpp b3427. It has been classified as very critical. This affects the function rpc_tensor. The manipulation leads to write-what-where condition.
This vulnerability is uniquely identified as CVE-2024-42479. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-42478 | ggerganov llama.cpp b3427 rpc_tensor out-of-bounds (GHSA-5vm9-p64x-gqw9)
1 year 7 months ago
A vulnerability was found in ggerganov llama.cpp b3427 and classified as problematic. Affected by this issue is the function rpc_tensor. The manipulation leads to out-of-bounds read.
This vulnerability is handled as CVE-2024-42478. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-42520 | TOTOLINK A3002R 4.0.0-B20230531.1404 /bin/boa formParentControl buffer overflow
1 year 7 months ago
A vulnerability has been found in TOTOLINK A3002R 4.0.0-B20230531.1404 and classified as critical. Affected by this vulnerability is the function formParentControl of the file /bin/boa. The manipulation leads to buffer overflow.
This vulnerability is known as CVE-2024-42520. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-33533 | Zimbra Collaboration Suite 9.0/10.0 Webmail Admin Interface cross site scripting
1 year 7 months ago
A vulnerability, which was classified as problematic, was found in Zimbra Collaboration Suite 9.0/10.0. Affected is an unknown function of the component Webmail Admin Interface. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-33533. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-27443 | Zimbra Collaboration Suite 9.0/10.0 CalendarInvite cross site scripting
1 year 7 months ago
A vulnerability, which was classified as problematic, has been found in Zimbra Collaboration Suite 9.0/10.0. This issue affects some unknown processing of the component CalendarInvite. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-27443. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-21550 | websockets SteVe up to 3.5.0/3.6.0/3.7.0 Websocket cross site scripting (ID 1526)
1 year 7 months ago
A vulnerability classified as problematic was found in websockets SteVe up to 3.5.0/3.6.0/3.7.0. This vulnerability affects unknown code of the component Websocket Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-21550. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-33535 | Zimbra Collaboration Suite 9.0/10.0 file inclusion
1 year 7 months ago
A vulnerability classified as problematic has been found in Zimbra Collaboration Suite 9.0/10.0. This affects an unknown part. The manipulation leads to file inclusion.
This vulnerability is uniquely identified as CVE-2024-33535. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-42477 | ggerganov llama.cpp b3427 rpc_tensor out-of-bounds (GHSA-mqp6-7pv6-fqjf)
1 year 7 months ago
A vulnerability was found in ggerganov llama.cpp b3427. It has been rated as problematic. Affected by this issue is the function rpc_tensor. The manipulation leads to out-of-bounds read.
This vulnerability is handled as CVE-2024-42477. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-6917 | Veribilim Software Veribase Order Management prior 4.010.2 os command injection
1 year 7 months ago
A vulnerability was found in Veribilim Software Veribase Order Management. It has been declared as very critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to os command injection.
This vulnerability is known as CVE-2024-6917. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-27442 | Zimbra Collaboration Suite 9.0/10.0 zmmailboxdmgr Local Privilege Escalation
1 year 7 months ago
A vulnerability was found in Zimbra Collaboration Suite 9.0/10.0. It has been classified as critical. Affected is an unknown function of the file zmmailboxdmgr. The manipulation leads to Local Privilege Escalation.
This vulnerability is traded as CVE-2024-27442. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com