2571
|
4.6 |
MEDIUM
Network
|
apache
|
nifi
|
Apache NiFi 1.10.0 through 1.27.0 and 2.0.0-M1 through 2.0.0-M3 support a description field for Parameters in a Parameter Context configuration that is vulnerable to cross-site scripting. An authenti…
|
CWE-79
Cross-site Scripting
|
CVE-2024-45477
|
2024-11-9 00:03 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2572
|
7.2 |
HIGH
Network
|
davidlingren
|
media_library_assistant
|
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in David Lingren Media Library Assistant allows Command Injection.This issue affects Media Lib…
|
CWE-78
OS Command
|
CVE-2024-51661
|
2024-11-9 00:02 |
2024-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2573
|
4.6 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to sanitize user inputs in the frontend that are used for redirection which allows for a one-click client-side path travers…
|
CWE-352
Origin Validation Error
|
CVE-2024-46872
|
2024-11-9 00:00 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2574
|
6.1 |
MEDIUM
Network
|
latex2html
|
latex2html
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Van Abel LaTeX2HTML allows Reflected XSS.This issue affects LaTeX2HTML: from n/a through 2…
|
CWE-79
Cross-site Scripting
|
CVE-2024-49673
|
2024-11-8 23:57 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2575
|
6.1 |
MEDIUM
Network
|
samglover
|
client_power_tools
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sam Glover Client Power Tools Portal allows Reflected XSS.This issue affects Client Power …
|
CWE-79
Cross-site Scripting
|
CVE-2024-49670
|
2024-11-8 23:57 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2576
|
5.4 |
MEDIUM
Network
|
affiliatexblocks
|
affiliatex
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AffiliateX allows Stored XSS.This issue affects AffiliateX: from n/a through 1.2.9.
|
CWE-79
Cross-site Scripting
|
CVE-2024-49692
|
2024-11-8 23:55 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2577
|
5.4 |
MEDIUM
Network
|
brainstormforce
|
astra_widgets
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Brainstorm Force Astra Widgets allows Stored XSS.This issue affects Astra Widgets: from n/…
|
CWE-79
Cross-site Scripting
|
CVE-2024-50439
|
2024-11-8 23:53 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2578
|
5.4 |
MEDIUM
Network
|
wpkoi
|
wpkoi_templates_for_elementor
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPKoi WPKoi Templates for Elementor allows Stored XSS.This issue affects WPKoi Templates f…
|
CWE-79
Cross-site Scripting
|
CVE-2024-49679
|
2024-11-8 23:52 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2579
|
6.1 |
MEDIUM
Network
|
themoyles
|
church_admin
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Andy Moyle Church Admin allows Reflected XSS.This issue affects Church Admin: from n/a bef…
|
CWE-79
Cross-site Scripting
|
CVE-2024-50438
|
2024-11-8 23:52 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2580
|
4.7 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
nvme-pci: fix race condition between reset and nvme_dev_disable()
nvme_dev_disable() modifies the dev->online_queues field, there…
|
CWE-362
Race Condition
|
CVE-2024-50135
|
2024-11-8 23:34 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|