231
|
5.4 |
MEDIUM
Network
|
sksdev
|
sksdev_toolkit
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in sksdev SKSDEV Toolkit allows Stored XSS.This issue affects SKSDEV Toolkit: from n/a throug…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-51595
|
2024-11-16 02:03 |
2024-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
232
|
5.4 |
MEDIUM
Network
|
snilesh
|
business
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Nilesh Shiragave Business allows Stored XSS.This issue affects Business: from n/a through …
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-51596
|
2024-11-16 02:01 |
2024-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
233
|
5.5 |
MEDIUM
Local
|
lenovo
|
dolby_vision_provisioning
|
A potential information disclosure vulnerability was reported in Lenovo's packaging of Dolby Vision Provisioning software prior to version 2.0.0.2 that could allow a local attacker to read files on t…
Update
|
CWE-276
Incorrect Default Permissions
|
CVE-2024-5474
|
2024-11-16 02:00 |
2024-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
234
|
9.1 |
CRITICAL
Network
github
|
enterprise_server
|
An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed resulting in unauthorized provisioning…
Update
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2024-9487
|
2024-11-16 01:57 |
2024-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
235
|
5.4 |
MEDIUM
Network
|
russellalbin
|
simple_business_manager
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Russell Albin Simple Business Manager allows Stored XSS.This issue affects Simple Business…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-51599
|
2024-11-16 01:55 |
2024-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
236
|
7.5 |
HIGH
Network
gradio_project
|
gradio
|
Gradio is an open-source Python package designed for quick prototyping. This vulnerability is a **lack of integrity check** on the downloaded FRP client, which could potentially allow attackers to in…
Update
|
NVD-CWE-Other
|
CVE-2024-47867
|
2024-11-16 01:44 |
2024-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
237
|
9.8 |
CRITICAL
Network
pedalo
|
pedalo_connector
|
The Pedalo Connector plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.5. This is due to insufficient restriction on the 'login_admin_user' function. T…
Update
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2024-9822
|
2024-11-16 01:41 |
2024-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
238
|
- |
|
-
|
-
|
parisneo/lollms-webui version 9.6 is vulnerable to Cross-Site Scripting (XSS) and Open Redirect due to inadequate input validation and processing of SVG files during the upload process. The XSS vulne…
New
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-5125
|
2024-11-16 01:35 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
239
|
7.8 |
HIGH
Local
|
samsung
|
android
|
Improper access control in ActivityManager prior to SMR Oct-2024 Release 1 in select Android 12, 13 and SMR Sep-2024 Release 1 in select Android 14 allows local attackers to execute privileged behavi…
Update
|
NVD-CWE-noinfo
|
CVE-2024-34662
|
2024-11-16 01:34 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
240
|
5.4 |
MEDIUM
Network
|
seothemes
|
display_terms_shortcode
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SEO Themes Display Terms Shortcode allows Stored XSS.This issue affects Display Terms Shor…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-51610
|
2024-11-16 01:32 |
2024-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|