Aggregator
CVE-2024-13032 | Antabot White-Jotter up to 0.2.2 Article Editor /admin/content/editor articleCover server-side request forgery
8 months 2 weeks ago
A vulnerability classified as problematic was found in Antabot White-Jotter up to 0.2.2. Affected by this vulnerability is an unknown functionality of the file /admin/content/editor of the component Article Editor. The manipulation of the argument articleCover leads to server-side request forgery.
This vulnerability is known as CVE-2024-13032. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-13031 | Antabot White-Jotter up to 0.2.2 Article Content Editor /admin/content/editor cross site scripting
8 months 2 weeks ago
A vulnerability classified as problematic has been found in Antabot White-Jotter up to 0.2.2. Affected is an unknown function of the file /admin/content/editor of the component Article Content Editor. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-13031. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2004-2618 | Pegasi Web Server 0.2.2 cross site scripting (EDB-23803 / ID 86641)
8 months 2 weeks ago
A vulnerability was found in Pegasi Web Server 0.2.2 and classified as problematic. This issue affects some unknown processing. The manipulation leads to basic cross site scripting.
The identification of this vulnerability is CVE-2004-2618. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #467694: Antabot White-Jotter 0.2.2 Authorization Bypass [Duplicate]
8 months 2 weeks ago
Submit #467694 / VDB-218303
vastzero
Submit #466551: Antabot White-Jotter 0.2.2 Server-Side Request Forgery [Accepted]
8 months 2 weeks ago
Submit #466551 / VDB-289765
vastzero
Submit #466550: Antabot White-Jotter 0.2.2 Stored Cross Site Scripting (XSS) [Duplicate]
8 months 2 weeks ago
Submit #466550 / VDB-289764
vastzero
Submit #466530: Antabot White-Jotter 0.2.2 Reflected Cross-Site Scripting (XSS) [Accepted]
8 months 2 weeks ago
Submit #466530 / VDB-289764
vastzero
CVE-2024-13030 | D-Link DIR-823G 1.0.2B05_20181207 Web Management Interface /HNAP1/ access control
8 months 2 weeks ago
A vulnerability was found in D-Link DIR-823G 1.0.2B05_20181207. It has been rated as critical. This issue affects the function SetAutoRebootSettings/SetClientInfo/SetDMZSettings/SetFirewallSettings/SetParentsControlInfo/SetQoSSettings/SetVirtualServerSettings of the file /HNAP1/ of the component Web Management Interface. The manipulation leads to improper access controls. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
The identification of this vulnerability is CVE-2024-13030. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply restrictive firewalling.
vuldb.com
Submit #467909: D-Link DIR823G V1.0.2B05_20181207 Improper Access Controls [Duplicate]
8 months 2 weeks ago
Submit #467909 / VDB-289763
wxhwxhwxh_mie
Submit #467907: D-Link DIR823G V1.0.2B05_20181207 Improper Access Controls [Duplicate]
8 months 2 weeks ago
Submit #467907 / VDB-289763
wxhwxhwxh_mie
Submit #467908: D-Link DIR823G V1.0.2B05_20181207 Improper Access Controls [Duplicate]
8 months 2 weeks ago
Submit #467908 / VDB-289763
wxhwxhwxh_mie
Submit #467905: D-Link DIR823G V1.0.2B05_20181207 Improper Access Controls [Duplicate]
8 months 2 weeks ago
Submit #467905 / VDB-289763
wxhwxhwxh_mie
Submit #467906: D-Link DIR823G V1.0.2B05_20181207 Improper Access Controls [Duplicate]
8 months 2 weeks ago
Submit #467906 / VDB-289763
wxhwxhwxh_mie
Submit #467904: D-Link DIR823G V1.0.2B05_20181207 Improper Access Controls [Duplicate]
8 months 2 weeks ago
Submit #467904 / VDB-289763
wxhwxhwxh_mie
Submit #467903: D-Link DIR823G V1.0.2B05_20181207 Improper Access Controls [Accepted]
8 months 2 weeks ago
Submit #467903 / VDB-289763
wxhwxhwxh_mie
CVE-2024-56745 | Linux Kernel up to 5.15.173/6.1.119/6.6.63/6.11.10/6.12.1 PCI reset_method_store memory leak
8 months 2 weeks ago
A vulnerability was found in Linux Kernel up to 5.15.173/6.1.119/6.6.63/6.11.10/6.12.1. It has been declared as critical. This vulnerability affects the function reset_method_store of the component PCI. The manipulation leads to memory leak.
This vulnerability was named CVE-2024-56745. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-56740 | Linux Kernel up to 6.12.1 localio nfs3_read_done res.replen memory corruption
8 months 2 weeks ago
A vulnerability was found in Linux Kernel up to 6.12.1. It has been classified as critical. This affects the function nfs3_read_done of the component localio. The manipulation of the argument res.replen leads to memory corruption.
This vulnerability is uniquely identified as CVE-2024-56740. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-56743 | Linux Kernel up to 6.12.1 nfs_common Privilege Escalation
8 months 2 weeks ago
A vulnerability was found in Linux Kernel up to 6.12.1 and classified as problematic. Affected by this issue is some unknown functionality of the component nfs_common. The manipulation leads to Privilege Escalation.
This vulnerability is handled as CVE-2024-56743. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-56756 | Linux Kernel up to 6.12.1 nvme-pci __nvme_alloc_host_mem allocation of resources
8 months 2 weeks ago
A vulnerability has been found in Linux Kernel up to 6.12.1 and classified as problematic. Affected by this vulnerability is the function __nvme_alloc_host_mem of the component nvme-pci. The manipulation leads to allocation of resources.
This vulnerability is known as CVE-2024-56756. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com