|
313101
|
5.3 |
MEDIUM
Network
|
umbraco
|
umbraco_cms
|
Umbraco is an ASP.NET CMS. Some endpoints in the Management API can return stack trace information, even when Umbraco is not in debug mode. This vulnerability is fixed in 14.1.2.
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2024-43376
|
2024-08-27 03:24 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313102
|
7.5 |
HIGH
Network
|
apolloconfig
|
apollo
|
An issue in apollocongif apollo v.2.2.0 allows a remote attacker to obtain sensitive information via a crafted request.
|
NVD-CWE-noinfo
|
CVE-2024-42662
|
2024-08-27 03:22 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313103
|
6.5 |
MEDIUM
Network
|
bitapps
|
contact_form_builder
|
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file deletion due to insuff…
|
CWE-22
Path Traversal
|
CVE-2024-7782
|
2024-08-27 03:21 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313104
|
9.0 |
CRITICAL
Network
|
bitapps
|
contact_form_builder
|
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file read and deletion due …
|
CWE-22
Path Traversal
|
CVE-2024-7777
|
2024-08-27 03:19 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313105
|
7.2 |
HIGH
Network
|
bitapps
|
contact_form_builder
|
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to generic SQL Injection via the id para…
|
CWE-89
SQL Injection
|
CVE-2024-7780
|
2024-08-27 03:19 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313106
|
4.8 |
MEDIUM
Network
|
bitapps
|
contact_form_builder
|
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary JavaScript file uploads due…
|
CWE-79
Cross-site Scripting
|
CVE-2024-7775
|
2024-08-27 03:18 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313107
|
7.2 |
HIGH
Network
|
bitapps
|
contact_form_builder
|
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to generic SQL Injection via the entryID…
|
CWE-89
SQL Injection
|
CVE-2024-7702
|
2024-08-27 03:15 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313108
|
5.4 |
MEDIUM
Network
|
givewp
|
givewp
|
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access and deletion of data due to a missing capability check on the 'handle_request' function…
|
CWE-862
Missing Authorization
|
CVE-2024-5941
|
2024-08-27 03:14 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313109
|
5.3 |
MEDIUM
Network
|
givewp
|
givewp
|
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'handle_request' function in all…
|
CWE-862
Missing Authorization
|
CVE-2024-5940
|
2024-08-27 03:14 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313110
|
5.3 |
MEDIUM
Network
|
givewp
|
givewp
|
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'setup_wizard' function in all version…
|
CWE-862
Missing Authorization
|
CVE-2024-5939
|
2024-08-27 03:12 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313111
|
- |
-
|
-
|
-
|
An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containing an Authority Key …
|
-
|
CVE-2024-45235
|
2024-08-27 02:35 |
2024-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313112
|
- |
-
|
-
|
-
|
A persistent (stored) cross-site scripting (XSS) vulnerability has been identified in Automad 2.0.0-alpha.4. This vulnerability enables an attacker to inject malicious JavaScript code into the templa…
|
-
|
CVE-2024-40111
|
2024-08-27 02:35 |
2024-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313113
|
- |
-
|
-
|
-
|
A host header injection vulnerability exists in the forgot password functionality of ArrowCMS version 1.0.0. By sending a specially crafted host header in the forgot password request, it is possible …
|
-
|
CVE-2024-42914
|
2024-08-27 02:35 |
2024-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313114
|
5.4 |
MEDIUM
Network
|
kjayvik
|
bus_ticket_reservation_system
|
Kashipara Bus Ticket Reservation System v1.0 0 is vulnerable to Incorrect Access Control via /deleteTicket.php.
|
NVD-CWE-Other
|
CVE-2024-42766
|
2024-08-27 02:35 |
2024-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313115
|
- |
-
|
-
|
-
|
SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_files.php imposes restrictions on edited files, attackers can still bypass these restri…
|
-
|
CVE-2024-42599
|
2024-08-27 02:35 |
2024-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313116
|
- |
-
|
-
|
-
|
A Stored Cross Site Scripting (XSS) vulnerability was found in "/music/ajax.php?action=save_playlist" in Kashipara Music Management System v1.0. This vulnerability allows remote attackers to execute …
|
-
|
CVE-2024-42787
|
2024-08-27 01:35 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313117
|
- |
-
|
-
|
-
|
An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containing a bit string that…
|
-
|
CVE-2024-45238
|
2024-08-27 01:35 |
2024-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313118
|
- |
-
|
-
|
-
|
An issue was discovered in the Docusign API package 8.142.14 for Salesforce. The Apttus_DocuApi__DocusignAuthentication__mdt object is installed via the marketplace from this package and stores some …
|
-
|
CVE-2024-39344
|
2024-08-27 01:35 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313119
|
- |
-
|
-
|
-
|
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in bPlugins LLC Flash & HTML5 Video.This issue affects Flash & HTML5 Video: from n/a through 2.5.31.
|
CWE-200
Information Exposure
|
CVE-2024-43319
|
2024-08-27 01:15 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313120
|
- |
-
|
-
|
-
|
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in gVectors Team wpForo Forum.This issue affects wpForo Forum: from n/a through 2.3.4.
|
-
|
CVE-2024-43289
|
2024-08-27 01:15 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313121
|
- |
-
|
-
|
-
|
A cross-site scripting (XSS) vulnerability in the Config-Create function of fastapi-admin pro v0.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the …
|
-
|
CVE-2024-42818
|
2024-08-27 01:15 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313122
|
- |
-
|
-
|
-
|
A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via /music/ajax.php?action=delete_genre.
|
-
|
CVE-2024-42791
|
2024-08-27 01:15 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313123
|
- |
-
|
-
|
-
|
A Stored Cross Site Scripting (XSS) vulnerability was found in "/music/ajax.php?action=save_music" in Kashipara Music Management System v1.0. This vulnerability allows remote attackers to execute arb…
|
-
|
CVE-2024-42788
|
2024-08-27 01:15 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313124
|
- |
-
|
-
|
-
|
The Ditty WordPress plugin before 3.1.46 re-introduced a previously fixed security issue (https://wpscan.com/vulnerability/80a9eb3a-2cb1-4844-9004-ba2554b2d46c/) in v3.1.39
|
-
|
CVE-2024-6715
|
2024-08-27 00:35 |
2024-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313125
|
- |
-
|
-
|
-
|
A vulnerability was found in code-projects Online Quiz Site 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file signupuser.php. The manipulation of th…
|
CWE-89
SQL Injection
|
CVE-2024-8169
|
2024-08-27 00:15 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313126
|
- |
-
|
-
|
-
|
A vulnerability was found in code-projects Online Bus Reservation Site 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file login.php. The man…
|
CWE-89
SQL Injection
|
CVE-2024-8168
|
2024-08-27 00:15 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313127
|
- |
-
|
-
|
-
|
A vulnerability was found in code-projects Job Portal 1.0. It has been classified as critical. Affected is an unknown function of the file /forget.php. The manipulation of the argument email/mobile l…
|
-
|
CVE-2024-8167
|
2024-08-27 00:15 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313128
|
- |
-
|
-
|
-
|
A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. This vulnerability exists…
|
-
|
CVE-2024-7988
|
2024-08-27 00:15 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313129
|
- |
-
|
-
|
-
|
A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™
that allows a threat actor to execute arbitrary code with System privileges. To exploit this vulnerabi…
|
-
|
CVE-2024-7987
|
2024-08-27 00:15 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313130
|
- |
-
|
-
|
-
|
XSS in the view page with the SLA column configured in Checkmk versions prior to 2.3.0p14, 2.2.0p33, 2.1.0p47 and 2.0.0 (EOL) allowed malicious users to execute arbitrary scripts by injecting HTML el…
|
-
|
CVE-2024-38859
|
2024-08-27 00:15 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313131
|
6.5 |
MEDIUM
Network
|
retool
|
retool
|
Retool (self-hosted enterprise) through 3.40.0 inserts resource authentication credentials into sent data. Credentials for users with "Use" permissions can be discovered (by an authenticated attacker…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2024-42056
|
2024-08-27 00:15 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313132
|
7.8 |
HIGH
Local
|
google
|
chrome
|
Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a crafted symbolic link. (Chromium security s…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2024-7980
|
2024-08-27 00:14 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313133
|
7.8 |
HIGH
Local
|
google
|
chrome
|
Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a crafted symbolic link. (Chromium security s…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2024-7979
|
2024-08-27 00:13 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313134
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security sev…
|
NVD-CWE-noinfo
|
CVE-2024-7972
|
2024-08-27 00:11 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313135
|
8.8 |
HIGH
Network
|
lopalopa
|
music_management_system
|
A SQL injection vulnerability in "/music/view_user.php" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter of View User Profile Page.
|
CWE-89
SQL Injection
|
CVE-2024-42786
|
2024-08-26 23:58 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313136
|
8.8 |
HIGH
Network
|
lopalopa
|
music_management_system
|
A SQL injection vulnerability in /music/index.php?page=view_playlist in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter.
|
CWE-89
SQL Injection
|
CVE-2024-42785
|
2024-08-26 23:57 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313137
|
9.8 |
CRITICAL
Network
|
lopalopa
|
music_management_system
|
A SQL injection vulnerability in "/music/controller.php?page=view_music" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter.
|
CWE-89
SQL Injection
|
CVE-2024-42784
|
2024-08-26 23:57 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313138
|
4.1 |
MEDIUM
Network
|
adobe
|
experience_manager
|
Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that could lead to a security feature bypass. An low-privileged attacker could leverage…
|
NVD-CWE-noinfo
|
CVE-2024-41849
|
2024-08-26 23:37 |
2024-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313139
|
5.4 |
MEDIUM
Network
|
adobe
|
experience_manager
|
Adobe Experience Manager versions 6.5.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vul…
|
CWE-79
Cross-site Scripting
|
CVE-2024-41848
|
2024-08-26 23:37 |
2024-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313140
|
5.4 |
MEDIUM
Network
|
adobe
|
experience_manager
|
Adobe Experience Manager versions 6.5.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vul…
|
CWE-79
Cross-site Scripting
|
CVE-2024-41847
|
2024-08-26 23:36 |
2024-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313141
|
5.4 |
MEDIUM
Network
|
adobe
|
experience_manager
|
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable …
|
CWE-79
Cross-site Scripting
|
CVE-2024-41846
|
2024-08-26 23:36 |
2024-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313142
|
- |
-
|
-
|
-
|
The req package before 3.43.4 for Go may send an unintended request when a malformed URL is provided, because cleanHost in http.go intentionally uses a "garbage in, garbage out" design.
|
-
|
CVE-2024-45258
|
2024-08-26 23:35 |
2024-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313143
|
5.4 |
MEDIUM
Network
|
adobe
|
experience_manager
|
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable …
|
CWE-79
Cross-site Scripting
|
CVE-2024-41845
|
2024-08-26 23:08 |
2024-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313144
|
5.4 |
MEDIUM
Network
|
adobe
|
experience_manager
|
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable …
|
CWE-79
Cross-site Scripting
|
CVE-2024-41844
|
2024-08-26 23:08 |
2024-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313145
|
5.4 |
MEDIUM
Network
|
adobe
|
experience_manager
|
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable …
|
CWE-79
Cross-site Scripting
|
CVE-2024-41843
|
2024-08-26 23:08 |
2024-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313146
|
4.8 |
MEDIUM
Network
|
adobe
|
experience_manager
|
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable …
|
CWE-79
Cross-site Scripting
|
CVE-2024-41842
|
2024-08-26 23:08 |
2024-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313147
|
5.4 |
MEDIUM
Network
|
adobe
|
experience_manager
|
Adobe Experience Manager versions 6.5.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vul…
|
CWE-79
Cross-site Scripting
|
CVE-2024-41841
|
2024-08-26 23:08 |
2024-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313148
|
9.8 |
CRITICAL
Network
|
dlink
|
di_8004w_firmware
|
D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in the jhttpd upgrade_filter_asp function.
|
NVD-CWE-noinfo
|
CVE-2024-44382
|
2024-08-26 22:58 |
2024-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313149
|
9.8 |
CRITICAL
Network
|
dlink
|
di_8004w_firmware
|
D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in jhttpd msp_info_htm function.
|
NVD-CWE-noinfo
|
CVE-2024-44381
|
2024-08-26 22:55 |
2024-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313150
|
- |
-
|
-
|
-
|
A vulnerability classified as problematic has been found in SourceCodester QR Code Bookmark System 1.0. Affected is an unknown function of the file /endpoint/update-bookmark.php of the component Para…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8154
|
2024-08-26 21:47 |
2024-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|