1741
|
- |
|
-
|
-
|
The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as deleting cards via CSRF…
|
-
|
CVE-2024-4532
|
2024-11-15 02:35 |
2024-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1742
|
- |
|
-
|
-
|
In Jenkins Delphix Plugin 3.0.1, a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower (DCT) connections is disabled by default.
|
-
|
CVE-2024-28161
|
2024-11-15 02:35 |
2024-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1743
|
6.2 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_payload: sanitize offset and length before calling skb_checksum()
If access to offset + length is larger than the …
|
NVD-CWE-noinfo
|
CVE-2024-50251
|
2024-11-15 02:31 |
2024-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1744
|
8.8 |
HIGH
Network
|
blrt
|
blrt_wp_embed
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Blrt Blrt WP Embed allows SQL Injection.This issue affects Blrt WP Embed: from n/a through 1.6.9.
|
CWE-89
SQL Injection
|
CVE-2024-51606
|
2024-11-15 02:17 |
2024-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1745
|
5.4 |
MEDIUM
Network
|
sap
|
commerce_backoffice
|
SAP Commerce Backoffice does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can cause limited impact…
|
CWE-79
Cross-site Scripting
|
CVE-2024-45278
|
2024-11-15 02:17 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1746
|
8.8 |
HIGH
Network
|
pluginhandy
|
amadiscount
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pluginhandy AmaDiscount allows SQL Injection.This issue affects AmaDiscount: from n/a through 1.0.
|
CWE-89
SQL Injection
|
CVE-2024-51608
|
2024-11-15 02:14 |
2024-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1747
|
4.8 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
Mattermost versions 9.11.x <= 9.11.2, and 9.5.x <= 9.5.10 fail to protect the mfa code against replay attacks, which allows an attacker to reuse the MFA code within ~30 seconds
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2024-36250
|
2024-11-15 02:11 |
2024-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1748
|
5.4 |
MEDIUM
Network
|
elsner
|
emoji_shortcode
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Elsner Technologies Pvt. Ltd. Emoji Shortcode allows Stored XSS.This issue affects Emoji S…
|
CWE-79
Cross-site Scripting
|
CVE-2024-51609
|
2024-11-15 02:10 |
2024-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1749
|
7.1 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
fsdax: dax_unshare_iter needs to copy entire blocks
The code that copies data from srcmap to iomap in dax_unshare_iter is
very ve…
|
NVD-CWE-noinfo
|
CVE-2024-50250
|
2024-11-15 02:04 |
2024-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1750
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ACPI: CPPC: Make rmw_lock a raw_spin_lock
The following BUG was triggered:
=============================
[ BUG: Invalid wait con…
|
NVD-CWE-noinfo
|
CVE-2024-50249
|
2024-11-15 02:01 |
2024-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|