1081
|
4.6 |
MEDIUM
Network
|
radixiot
|
mango
|
MangoOS before 5.2.0 was discovered to contain a Client-Side Template Injection (CSTI) vulnerability via the Platform Management Edit page.
Update
|
CWE-94
Code Injection
|
CVE-2024-37846
|
2024-11-6 01:03 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1082
|
5.4 |
MEDIUM
Network
|
radixiot
|
mango
|
A stored cross-site scripting (XSS) vulnerability in MangoOS before 5.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-37844
|
2024-11-6 01:03 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1083
|
9.8 |
CRITICAL
Network
woocommerce
|
product_vendors
|
Missing Authorization vulnerability in Woo WooCommerce Product Vendors.This issue affects WooCommerce Product Vendors: from n/a through 2.2.1.
Update
|
CWE-862
Missing Authorization
|
CVE-2023-51494
|
2024-11-6 01:01 |
2024-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1084
|
5.4 |
MEDIUM
Network
|
cisco
|
firepower_management_center
|
A vulnerability in the web-based management interface of Cisco FMC Software could allow an authenticated, remote attacker to store malicious content for use in XSS attacks. This vulnerability is due …
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-20387
|
2024-11-6 01:00 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1085
|
4.7 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in Compositing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: M…
Update
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2023-7013
|
2024-11-6 00:57 |
2024-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1086
|
7.5 |
HIGH
Network
bricksforge
|
bricksforge
|
Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17.
Update
|
CWE-862
Missing Authorization
|
CVE-2024-31244
|
2024-11-6 00:52 |
2024-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1087
|
7.5 |
HIGH
Network
bricksforge
|
bricksforge
|
Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17.
Update
|
CWE-862
Missing Authorization
|
CVE-2024-31243
|
2024-11-6 00:52 |
2024-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1088
|
8.8 |
HIGH
Network
|
radixiot
|
mangoapi mango
|
An arbitrary file upload vulnerability in MangoOS before 5.1.4 and Mango API before 4.5.5 allows attackers to execute arbitrary code via a crafted file.
Update
|
CWE-22
Path Traversal
|
CVE-2024-37847
|
2024-11-6 00:47 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1089
|
9.8 |
CRITICAL
Network
tainacan
|
tainacan
|
Missing Authorization vulnerability in Tainacan.Org Tainacan.This issue affects Tainacan: from n/a through 0.20.7.
Update
|
CWE-862
Missing Authorization
|
CVE-2024-30529
|
2024-11-6 00:46 |
2024-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1090
|
9.8 |
CRITICAL
Network
upqode
|
whizzy
|
Missing Authorization vulnerability in UPQODE Whizzy.This issue affects Whizzy: from n/a through 1.1.18.
Update
|
CWE-862
Missing Authorization
|
CVE-2024-30544
|
2024-11-6 00:45 |
2024-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|