|
312051
|
5.4 |
MEDIUM
Network
|
elementor
|
website_builder
|
The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url parameter of multiple widgets in all versions up to, and in…
|
CWE-79
Cross-site Scripting
|
CVE-2024-5416
|
2024-09-26 23:37 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312052
|
- |
-
|
-
|
-
|
Gigastone TR1 Travel Router R101 v1.0.2 is vulnerable to Command Injection. This allows an authenticated attacker to execute arbitrary commands on the device by sending a crafted HTTP request to the …
|
-
|
CVE-2024-44678
|
2024-09-26 23:35 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312053
|
- |
-
|
-
|
-
|
An issue was discovered in AdaCore ada_web_services 20.0 allows an attacker to escalate privileges and steal sessions via the Random_String() function in the src/core/aws-utils.adb module.
|
-
|
CVE-2024-41708
|
2024-09-26 23:35 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312054
|
- |
-
|
-
|
-
|
OpenSlides 4.0.15 verifies passwords by comparing password hashes using a function with content-dependent runtime. This can allow attackers to obtain information about the password hash using a timin…
|
-
|
CVE-2024-22893
|
2024-09-26 23:35 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312055
|
8.8 |
HIGH
Network
|
themekraft
|
buddyforms
|
The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to privilege escalation in all versions up to…
|
NVD-CWE-noinfo
|
CVE-2024-8246
|
2024-09-26 23:00 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312056
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
A library injection issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to modify protected parts of t…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2024-44168
|
2024-09-26 22:56 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312057
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. Processing a maliciously crafted texture may lead to…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-44161
|
2024-09-26 22:56 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312058
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. A malicious application may be able to access private information.
|
NVD-CWE-noinfo
|
CVE-2024-44163
|
2024-09-26 22:55 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312059
|
7.1 |
HIGH
Local
|
apple
|
macos ipados iphone_os
|
This issue was addressed with improved checks. This issue is fixed in iOS 17.7 and iPadOS 17.7, macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to bypass Privacy preferenc…
|
NVD-CWE-noinfo
|
CVE-2024-44164
|
2024-09-26 22:54 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312060
|
7.5 |
HIGH
Network
|
apple
|
macos iphone_os ipados visionos
|
A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7, iOS 17.7 and iPadOS 17.7, visionOS 2, iOS 18 and iPadOS 18, macOS Sonoma 14.7, macOS Sequoia 15. Network t…
|
NVD-CWE-noinfo
|
CVE-2024-44165
|
2024-09-26 22:53 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312061
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to access user-s…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2024-44166
|
2024-09-26 22:47 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312062
|
5.4 |
MEDIUM
Network
|
elizsoftware
|
panel
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Eliz Software Panel allows Stored XSS.This issue affects Panel: before v2.3.24.
|
CWE-79
Cross-site Scripting
|
CVE-2024-5959
|
2024-09-26 22:39 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312063
|
- |
-
|
-
|
-
|
An issue in TheGreenBow Windows Standard VPN Client 6.87.108 (and older), Windows Enterprise VPN Client 6.87.109 (and older), Windows Enterprise VPN Client 7.5.007 (and older), Android VPN Client 6.4…
|
-
|
CVE-2024-45750
|
2024-09-26 22:32 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312064
|
- |
-
|
-
|
-
|
A vulnerability in the UDP packet validation code of Cisco SD-WAN vEdge Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected system.
…
|
-
|
CVE-2024-20496
|
2024-09-26 22:32 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312065
|
- |
-
|
-
|
-
|
A vulnerability in the SSH server of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, remote attacker to impersonate a Cisco Catalyst Center appliance.
This vulner…
|
-
|
CVE-2024-20350
|
2024-09-26 22:32 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312066
|
- |
-
|
-
|
-
|
dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/doAdminAction.php?act=delCate&id=31
|
-
|
CVE-2024-46600
|
2024-09-26 22:32 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312067
|
- |
-
|
-
|
-
|
dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=addCate
|
-
|
CVE-2024-46485
|
2024-09-26 22:32 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312068
|
- |
-
|
-
|
-
|
VLC media player 3.0.20 and earlier is vulnerable to denial of service through an integer overflow which could be triggered with a maliciously crafted mms stream (heap based overflow). If successful,…
|
-
|
CVE-2024-46461
|
2024-09-26 22:32 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312069
|
- |
-
|
-
|
-
|
Insertion of Sensitive Information into Log File vulnerability in StylemixThemes Masterstudy LMS Starter.This issue affects Masterstudy LMS Starter: from n/a through 1.1.8.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2024-43990
|
2024-09-26 22:32 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312070
|
- |
-
|
-
|
-
|
HCL Nomad server on Domino is affected by an open proxy vulnerability in which an unauthenticated attacker can mask their original source IP address. This may enable an attacker to trick the user in…
|
-
|
CVE-2024-30128
|
2024-09-26 22:32 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312071
|
- |
-
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Talent Software BAP Automation allows Stored XSS.This issue affects BAP Automation: before…
|
CWE-79
Cross-site Scripting
|
CVE-2024-4657
|
2024-09-26 22:32 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312072
|
- |
-
|
-
|
-
|
Improper verification of cryptographic signature during installation of a Printer driver via the TeamViewer_service.exe component of TeamViewer Remote Clients prior version 15.58.4 for Windows allows…
|
-
|
CVE-2024-7481
|
2024-09-26 22:32 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312073
|
- |
-
|
-
|
-
|
Improper verification of cryptographic signature during installation of a VPN driver via the TeamViewer_service.exe component of TeamViewer Remote Clients prior version 15.58.4 for Windows allows an …
|
-
|
CVE-2024-7479
|
2024-09-26 22:32 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312074
|
5.5 |
MEDIUM
Network
|
-
|
-
|
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin debug settings in all versions up to, and including, 6.4.1 due to insufficient input sanitization and …
|
CWE-79
Cross-site Scripting
|
CVE-2024-9169
|
2024-09-26 22:32 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312075
|
7.5 |
HIGH
Network
|
-
|
-
|
An unauthenticated remote attacker can causes the CODESYS web server to access invalid memory which results in a DoS.
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2024-8175
|
2024-09-26 22:32 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312076
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.6.1 via the woof_messenger_re…
|
CWE-862
Missing Authorization
|
CVE-2024-7491
|
2024-09-26 22:32 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312077
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.9.1. This is due to missing nonce valida…
|
CWE-352
Origin Validation Error
|
CVE-2024-7386
|
2024-09-26 22:32 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312078
|
- |
-
|
-
|
-
|
Cross-Site Scripting (XSS) vulnerability in the Oct8ne system. This flaw could allow an attacker to embed harmful JavaScript code into the body of a chat message. This manipulation occurs when the ch…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9141
|
2024-09-26 22:32 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312079
|
- |
-
|
-
|
-
|
Integer overflow in Skia in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
|
-
|
CVE-2024-9123
|
2024-09-26 22:32 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312080
|
- |
-
|
-
|
-
|
Type Confusion in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
|
-
|
CVE-2024-9122
|
2024-09-26 22:32 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312081
|
- |
-
|
-
|
-
|
Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security sev…
|
-
|
CVE-2024-9121
|
2024-09-26 22:32 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312082
|
- |
-
|
-
|
-
|
Use after free in Dawn in Google Chrome on Windows prior to 129.0.6668.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
|
-
|
CVE-2024-9120
|
2024-09-26 22:32 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312083
|
- |
-
|
-
|
-
|
Franklin Fueling Systems TS-550 EVO versions prior to 2.26.4.8967 possess a file that can be read arbitrarily that could allow an attacker obtain administrator credentials.
|
-
|
CVE-2024-8497
|
2024-09-26 22:32 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312084
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions hooked via AJAX like wpeg_settings and …
|
CWE-862
Missing Authorization
|
CVE-2024-8437
|
2024-09-26 22:32 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312085
|
9.9 |
CRITICAL
Network
|
-
|
-
|
The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to SQL Injection via the 'edit_imageId' and 'edit_imageDelete' parameters in all versions up to, and including, 4.8.5…
|
CWE-89
SQL Injection
|
CVE-2024-8436
|
2024-09-26 22:32 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312086
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' attribute within the 'wp:radio-p…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8267
|
2024-09-26 22:32 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312087
|
- |
-
|
-
|
-
|
Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and before is vulnerable to a message forgery / impersonation issue. Attackers can abuse the UpdateOTRAck method to send ephemeral messages as…
|
-
|
CVE-2024-46936
|
2024-09-26 22:32 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312088
|
- |
-
|
-
|
-
|
IceCMS v3.4.7 and before was discovered to contain a hardcoded JWT key, allowing an attacker to forge JWT authentication information.
|
-
|
CVE-2024-46612
|
2024-09-26 22:32 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312089
|
- |
-
|
-
|
-
|
Incorrect access control in IceCMS v3.4.7 and before allows attackers to authenticate by entering any arbitrary values as the username and password via the loginAdmin method in the UserController.jav…
|
-
|
CVE-2024-46607
|
2024-09-26 22:32 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312090
|
- |
-
|
-
|
-
|
Cursor is an artificial intelligence code editor. Prior to version 0.41.0, if a user on macOS has granted Cursor access to the camera or microphone, any program that is run on the machine is able to …
|
CWE-277
Insecure Inherited Permissions
|
CVE-2024-45599
|
2024-09-26 22:32 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312091
|
- |
-
|
-
|
-
|
An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_playlist in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to delet…
|
-
|
CVE-2024-42797
|
2024-09-26 22:32 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312092
|
- |
-
|
-
|
-
|
Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point man…
|
-
|
CVE-2024-42507
|
2024-09-26 22:32 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312093
|
- |
-
|
-
|
-
|
Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point man…
|
-
|
CVE-2024-42506
|
2024-09-26 22:32 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312094
|
- |
-
|
-
|
-
|
Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point man…
|
-
|
CVE-2024-42505
|
2024-09-26 22:32 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312095
|
- |
-
|
-
|
-
|
Proxmox Virtual Environment is an open-source server management platform for enterprise virtualization. Insufficient safeguards against malicious API response values allow authenticated attackers wit…
|
-
|
CVE-2024-21545
|
2024-09-26 22:32 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312096
|
- |
-
|
-
|
-
|
Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via crafted zip file when installing a new add-on.
|
-
|
CVE-2023-26691
|
2024-09-26 22:32 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312097
|
- |
-
|
-
|
-
|
File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via File Manager/Editor component in the vendor or admin menu.
|
-
|
CVE-2023-26690
|
2024-09-26 22:32 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312098
|
- |
-
|
-
|
-
|
An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request.
|
-
|
CVE-2023-26689
|
2024-09-26 22:32 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312099
|
- |
-
|
-
|
-
|
Cross Site Scripting (XSS) vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the product_data parameter of add/edit product in the administration interface.
|
-
|
CVE-2023-26688
|
2024-09-26 22:32 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312100
|
- |
-
|
-
|
-
|
Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to obtain sensitive information via the product_data parameter in the PDF Add-on.
|
-
|
CVE-2023-26687
|
2024-09-26 22:32 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|