2.3

CVSS4.0

CVE-2024-47166 - One-level read path traversal in `/custom_component` in Gradio

Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **one-level read path traversal** in the `/custom_component` endpoint. Attackers can exploit this flaw to access and leak source code from custom Gradio components by manipulating the file path in …

📅 Published: Oct. 10, 2024, 9:48 p.m. 🔄 Last Modified: Oct. 17, 2024, 4:48 p.m.

6.9

CVSS4.0

CVE-2024-47167 - SSRF in the path parameter of /queue/join in Gradio

Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to **Server-Side Request Forgery (SSRF)** in the `/queue/join` endpoint. Gradio’s `async_save_url_to_cache` function allows attackers to force the Gradio server to send HTTP requests to user-controlle…

📅 Published: Oct. 10, 2024, 9:47 p.m. 🔄 Last Modified: Oct. 17, 2024, 4:53 p.m.

2.3

CVSS4.0

CVE-2024-47168 - The `enable_monitoring` flag set to `False` does not disable monitoring in Gradio

Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves data exposure due to the enable_monitoring flag not properly disabling monitoring when set to False. Even when monitoring is supposedly disabled, an attacker or unauthorized user can still access the…

📅 Published: Oct. 10, 2024, 9:44 p.m. 🔄 Last Modified: Oct. 17, 2024, 5 p.m.

5.1

CVSS4.0

CVE-2024-9815 - Codezips Tourist Management System create-package.php unrestricted upload

A vulnerability has been found in Codezips Tourist Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/create-package.php. The manipulation of the argument packageimage leads to unrestricted upload. The attack can be launch…

📅 Published: Oct. 10, 2024, 9:31 p.m. 🔄 Last Modified: Oct. 17, 2024, 2:52 p.m.

6.9

CVSS4.0

CVE-2024-9814 - Codezips Pharmacy Management System update.php sql injection

A vulnerability, which was classified as critical, was found in Codezips Pharmacy Management System 1.0. Affected is an unknown function of the file product/update.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been dis…

📅 Published: Oct. 10, 2024, 9:31 p.m. 🔄 Last Modified: Oct. 17, 2024, 2:48 p.m.

9.5

CVSS4.0

CVE-2024-9487 - An Improper Verification of Cryptographic Signature vulnerability was identified in GitHub Enterpri…

An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed resulting in unauthorized provisioning of users and access to the instance. Exploitation required the encrypted assertions feature to be e…

📅 Published: Oct. 10, 2024, 9:08 p.m. 🔄 Last Modified: Nov. 15, 2024, 4:57 p.m.

6.9

CVSS4.0

CVE-2024-9813 - Codezips Pharmacy Management System register.php sql injection

A vulnerability, which was classified as critical, has been found in Codezips Pharmacy Management System 1.0. This issue affects some unknown processing of the file product/register.php. The manipulation of the argument category leads to sql injection. The attack may be initiated remotely. The expl…

📅 Published: Oct. 10, 2024, 9 p.m. 🔄 Last Modified: Oct. 15, 2024, 7:23 p.m.

6.9

CVSS4.0

CVE-2024-9812 - code-projects Crud Operation System delete.php sql injection

A vulnerability classified as critical was found in code-projects Crud Operation System 1.0. This vulnerability affects unknown code of the file delete.php. The manipulation of the argument sid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the publi…

📅 Published: Oct. 10, 2024, 9 p.m. 🔄 Last Modified: Oct. 15, 2024, 7:22 p.m.

7.2

CVSS3.1

CVE-2024-9180 - Vault Operators in Root Namespace May Elevate Their Privileges

A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s privileges to Vault’s root policy. Fixed in Vault Community Edition 1.18.0 and Vault Enterprise 1.18.0, 1.17.7, 1.16.11, and 1.15.16.

📅 Published: Oct. 10, 2024, 8:54 p.m. 🔄 Last Modified: Dec. 31, 2025, 12:49 a.m.

6.9

CVSS4.0

CVE-2024-9811 - code-projects Restaurant Reservation System filter3.php sql injection

A vulnerability classified as critical has been found in code-projects Restaurant Reservation System 1.0. This affects an unknown part of the file filter3.php. The manipulation of the argument company leads to sql injection. It is possible to initiate the attack remotely. The exploit has been discl…

📅 Published: Oct. 10, 2024, 8:31 p.m. 🔄 Last Modified: Oct. 15, 2024, 7:22 p.m.
Total resulsts: 349182
Page 8324 of 34,919
« previous page » next page
Filters