851
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to access user-s…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2024-44166
|
2024-09-26 22:47 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
852
|
5.4 |
MEDIUM
Network
|
elizsoftware
|
panel
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Eliz Software Panel allows Stored XSS.This issue affects Panel: before v2.3.24.
|
CWE-79
Cross-site Scripting
|
CVE-2024-5959
|
2024-09-26 22:39 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
853
|
7.2 |
HIGH
Network
|
i13websolution
|
video_carousel_slider_with_lightbox
|
The video carousel slider with lightbox plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.0.6 due to insufficient escaping on the user…
|
CWE-89
SQL Injection
|
CVE-2019-25212
|
2024-09-26 22:36 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
854
|
5.4 |
MEDIUM
Network
|
joplin_project
|
joplin
|
Joplin is a free, open source note taking and to-do application. A Cross site scripting (XSS) vulnerability in affected versions allows clicking on an untrusted image link to execute arbitrary shell …
|
CWE-79
Cross-site Scripting
|
CVE-2023-39517
|
2024-09-26 22:36 |
2024-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
855
|
5.5 |
MEDIUM
Network
|
-
|
-
|
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.15.27 due to insuf…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8633
|
2024-09-26 22:32 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
856
|
- |
|
-
|
-
|
Incorrect Authorization vulnerability in National Keep Cyber Security Services CyberMath allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects CyberMath: before CYBM.2408…
|
CWE-863
Incorrect Authorization
|
CVE-2024-7108
|
2024-09-26 22:32 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
857
|
- |
|
-
|
-
|
Files or Directories Accessible to External Parties vulnerability in National Keep Cyber Security Services CyberMath allows Collect Data from Common Resource Locations.This issue affects CyberMath: b…
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2024-7107
|
2024-09-26 22:32 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
858
|
6.8 |
MEDIUM
Network
|
-
|
-
|
Multiple plugins and/or themes for WordPress are vulnerable to Limited File Upload in various versions. This is due to a lack of proper checks to ensure lower-privileged roles cannot upload .css and …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-8725
|
2024-09-26 22:32 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
859
|
7.2 |
HIGH
Network
|
-
|
-
|
The Advanced File Manager plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 5.2.8 via the 'fma_locale' parameter. This makes it possible for …
|
-
|
CVE-2024-8704
|
2024-09-26 22:32 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
860
|
7.5 |
HIGH
Network
|
-
|
-
|
The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.8. This makes it possible for a…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-8126
|
2024-09-26 22:32 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|