481
|
- |
|
-
|
-
|
A cross-site scripting (XSS) vulnerability in Grav v1.7.45 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
New
|
-
|
CVE-2024-35498
|
2025-01-8 01:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
482
|
- |
|
-
|
-
|
An Escalation of Privilege security vulnerability was found in SecureAge Security Suite software 7.0.x before 7.0.38, 7.1.x before 7.1.11, 8.0.x before 8.0.18, and 8.1.x before 8.1.18 that allows arb…
New
|
-
|
CVE-2024-46622
|
2025-01-8 01:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
483
|
- |
|
-
|
-
|
A vulnerability has been found in SourceCodester Home Clean Services Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /public_h…
New
|
-
|
CVE-2025-0294
|
2025-01-8 00:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
484
|
- |
|
-
|
-
|
Open Redirect vulnerability in Pnetlab 5.3.11 allows an attacker to manipulate URLs to redirect users to arbitrary external websites via a crafted script
Update
|
-
|
CVE-2024-51112
|
2025-01-8 00:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
485
|
5.3 |
MEDIUM
Network
-
|
-
|
IBM Security ReaQta 3.12 returns sensitive information in an HTTP response that could be used in further attacks against the system.
|
CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere
|
CVE-2024-45640
|
2025-01-7 22:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
486
|
4.9 |
MEDIUM
Network
|
-
|
-
|
IBM Security ReaQta 3.12 could allow a privileged user to cause a denial of service by sending multiple administration requests due to improper allocation of resources.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2024-45100
|
2025-01-7 22:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
487
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several user meta parameters in al…
|
CWE-79
Cross-site Scripting
|
CVE-2024-12738
|
2025-01-7 22:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
488
|
- |
|
-
|
-
|
Exposure of Environmental Variables and arbitrary INI file values to an Unauthorized Actor vulnerability in The Document Foundation LibreOffice.
URLs could be constructed which expanded environme…
|
-
|
CVE-2024-12426
|
2025-01-7 22:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
489
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.5 d…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-12131
|
2025-01-7 22:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
490
|
5.3 |
MEDIUM
Network
-
|
-
|
IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3
could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This i…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2024-52893
|
2025-01-7 21:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|