471
|
- |
|
-
|
-
|
Discourse is an open source platform for community discussion. In affected versions an attacker can make craft an XHR request to poison the anonymous cache (for example, the cache may have a response…
|
CWE-346
Origin Validation Error
|
CVE-2024-55948
|
2025-02-5 06:15 |
2025-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
472
|
2.7 |
LOW
Network
|
-
|
-
|
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. This inform…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2024-45658
|
2025-02-5 06:15 |
2025-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
473
|
5.0 |
MEDIUM
Local
|
-
|
-
|
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a local privileged user to perform unauthorized actions due to incorrect permissions assignment.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2024-45657
|
2025-02-5 06:15 |
2025-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
474
|
5.9 |
MEDIUM
Network
|
-
|
-
|
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized acto…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2024-43187
|
2025-02-5 06:15 |
2025-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
475
|
6.1 |
MEDIUM
Network
|
-
|
-
|
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript cod…
|
CWE-79
Cross-site Scripting
|
CVE-2024-40700
|
2025-02-5 06:15 |
2025-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
476
|
6.5 |
MEDIUM
Network
|
-
|
-
|
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transm…
|
CWE-352
Origin Validation Error
|
CVE-2024-35138
|
2025-02-5 06:15 |
2025-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
477
|
- |
|
-
|
-
|
The Widget4Call WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against …
|
-
|
CVE-2024-13099
|
2025-02-5 06:15 |
2025-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
478
|
- |
|
-
|
-
|
The WordPress Email Newsletter WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be …
|
-
|
CVE-2024-13098
|
2025-02-5 06:15 |
2025-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
479
|
- |
|
-
|
-
|
The WP Finance WordPress plugin through 1.3.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against h…
|
-
|
CVE-2024-13097
|
2025-02-5 06:15 |
2025-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
480
|
- |
|
-
|
-
|
The WP Finance WordPress plugin through 1.3.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored …
|
-
|
CVE-2024-13096
|
2025-02-5 06:15 |
2025-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|