291
|
5.4 |
MEDIUM
Network
|
rafelsanso
|
gmap_point_list
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Rafel Sansó Gmap Point List allows Stored XSS.This issue affects Gmap Point List: from n/a…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-51594
|
2024-11-16 02:15 |
2024-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
292
|
4.3 |
MEDIUM
Network
|
github
|
enterprise_server
|
An information disclosure vulnerability was identified in GitHub Enterprise Server via attacker uploaded asset URL allowing the attacker to retrieve metadata information of a user who clicks on the U…
Update
|
NVD-CWE-noinfo
|
CVE-2024-9539
|
2024-11-16 02:15 |
2024-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
293
|
4.8 |
MEDIUM
Network
|
mendix
|
mendix
|
A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.16.0 only if the basic authentication mechanism is used by the application), Mendix Runtime V10.12 (All versions < V10.12…
Update
|
CWE-362
Race Condition
|
CVE-2024-50313
|
2024-11-16 02:12 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
294
|
4.4 |
MEDIUM
Local
|
lollms
|
lollms
|
A path traversal vulnerability exists in the api open_personality_folder endpoint of parisneo/lollms-webui. This vulnerability allows an attacker to read any folder in the personality_folder on the v…
Update
|
CWE-23
Relative Path Traversal
|
CVE-2024-6985
|
2024-11-16 02:10 |
2024-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
295
|
5.4 |
MEDIUM
Network
|
mysticalthemes
|
meta_store_elements
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in bnayawpguy Meta Store Elements allows DOM-Based XSS.This issue affects Meta Store Elements…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-51592
|
2024-11-16 02:04 |
2024-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
296
|
5.4 |
MEDIUM
Network
|
sksdev
|
sksdev_toolkit
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in sksdev SKSDEV Toolkit allows Stored XSS.This issue affects SKSDEV Toolkit: from n/a throug…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-51595
|
2024-11-16 02:03 |
2024-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
297
|
5.4 |
MEDIUM
Network
|
snilesh
|
business
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Nilesh Shiragave Business allows Stored XSS.This issue affects Business: from n/a through …
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-51596
|
2024-11-16 02:01 |
2024-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
298
|
5.5 |
MEDIUM
Local
|
lenovo
|
dolby_vision_provisioning
|
A potential information disclosure vulnerability was reported in Lenovo's packaging of Dolby Vision Provisioning software prior to version 2.0.0.2 that could allow a local attacker to read files on t…
Update
|
CWE-276
Incorrect Default Permissions
|
CVE-2024-5474
|
2024-11-16 02:00 |
2024-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
299
|
9.1 |
CRITICAL
Network
github
|
enterprise_server
|
An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed resulting in unauthorized provisioning…
Update
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2024-9487
|
2024-11-16 01:57 |
2024-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
300
|
5.4 |
MEDIUM
Network
|
russellalbin
|
simple_business_manager
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Russell Albin Simple Business Manager allows Stored XSS.This issue affects Simple Business…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-51599
|
2024-11-16 01:55 |
2024-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|