1071
|
5.4 |
MEDIUM
Network
|
crm2go
|
crm2go
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CRM 2go allows DOM-Based XSS.This issue affects CRM 2go: from n/a through 1.0.
|
CWE-79
Cross-site Scripting
|
CVE-2024-52350
|
2024-11-15 05:22 |
2024-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1072
|
6.8 |
MEDIUM
Physics
|
-
|
-
|
Windows USB Video Class System Driver Elevation of Privilege Vulnerability
|
CWE-125
Out-of-bounds Read
|
CVE-2024-43637
|
2024-11-15 05:15 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1073
|
8.1 |
HIGH
Network
|
-
|
-
|
LightGBM Remote Code Execution Vulnerability
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2024-43598
|
2024-11-15 05:15 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1074
|
8.1 |
HIGH
Network
|
ampache
|
ampache
|
Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSRF tokens when activating or deactivating controlle…
|
CWE-352
Origin Validation Error
|
CVE-2024-51484
|
2024-11-15 05:14 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1075
|
5.4 |
MEDIUM
Network
|
ampache
|
ampache
|
Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing does not adequately validate CSRF tokens when users delete messages. This vulner…
|
CWE-352
Origin Validation Error
|
CVE-2024-51488
|
2024-11-15 05:12 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1076
|
8.1 |
HIGH
Network
|
ampache
|
ampache
|
Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSRF tokens when activating or deactivating plugins. …
|
CWE-352
Origin Validation Error
|
CVE-2024-51485
|
2024-11-15 05:06 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1077
|
8.4 |
HIGH
Network
|
ampache
|
ampache
|
Ampache is a web based audio/video streaming application and file manager. The vulnerability exists in the interface section of the Ampache menu, where users can change the "Custom URL?-?Favicon". Th…
|
CWE-79
Cross-site Scripting
|
CVE-2024-51486
|
2024-11-15 04:55 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1078
|
4.3 |
MEDIUM
Network
|
futuriowp
|
futurio_extra
|
The Futurio Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.0.13 via the 'elementor-template' shortcode due to insufficient restrictions on wh…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-10695
|
2024-11-15 04:44 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1079
|
6.1 |
MEDIUM
Network
|
wpplugin
|
contact_form_7_redirect_\&_thank_you_page
|
The Contact Form 7 Redirect & Thank You Page plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 1.0.6 due to insufficie…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10685
|
2024-11-15 04:40 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1080
|
7.5 |
HIGH
Network
onedev_project
|
onedev
|
OneDev is a Git server with CI/CD, kanban, and packages. A vulnerability in versions prior to 11.0.9 allows unauthenticated users to read arbitrary files accessible by the OneDev server process. This…
|
CWE-22
Path Traversal
|
CVE-2024-45309
|
2024-11-15 04:39 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|