261
|
9.8 |
CRITICAL
Network
digitalzoomstudio
|
zoomsounds
|
The ZoomSounds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'savepng.php' file in versions up to, and including, 5.96. This makes it possibl…
Update
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-4449
|
2024-10-31 03:06 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
262
|
6.1 |
MEDIUM
Network
|
openrefine
|
openrefine
|
OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `/extension/gdata/authorized` endpoint includes the `state` GET parameter verbatim in a `<script>` tag …
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-47878
|
2024-10-31 03:01 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263
|
5.5 |
MEDIUM
Local
|
apple
|
macos iphone_os ipados watchos visionos tvos
|
The issue was addressed with improved checks. This issue is fixed in tvOS 18.1, iOS 18.1 and iPadOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, macOS Ventura 13.7.1, macOS Sonoma 14.7.1, watchOS 11.1, vision…
New
|
NVD-CWE-noinfo
|
CVE-2024-44302
|
2024-10-31 02:49 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.1, macOS Sonoma 14.7.1. A malicious application may be able to modify protected parts of the file system.
New
|
NVD-CWE-noinfo
|
CVE-2024-44247
|
2024-10-31 02:49 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265
|
8.8 |
HIGH
Network
|
pickplugins
|
post_grid
|
The Post Grid plugin for WordPress is vulnerable to blind SQL Injection via post metadata in versions up to, and including, 2.1.12 due to insufficient escaping on the user supplied parameter and lack…
Update
|
CWE-89
SQL Injection
|
CVE-2021-4450
|
2024-10-31 02:47 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266
|
7.2 |
HIGH
Network
|
nintechnet
|
ninjafirewall
|
The NinjaFirewall plugin for WordPress is vulnerable to Authenticated PHAR Deserialization in versions up to, and including, 4.3.3. This allows authenticated attackers to perform phar deserialization…
Update
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2021-4451
|
2024-10-31 02:44 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267
|
6.9 |
MEDIUM
Network
|
openrefine
|
openrefine
|
OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `export-rows` command can be used in such a way that it reflects part of the request verbatim, with a C…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-47880
|
2024-10-31 02:42 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268
|
- |
|
-
|
-
|
File Upload vulnerability in Prison Management System v.1.0 allows a remote attacker to execute arbitrary code via the file upload component.
New
|
-
|
CVE-2024-48594
|
2024-10-31 02:35 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269
|
- |
|
-
|
-
|
LyLme Spage <=1.6.0 is vulnerable to SQL Injection via /admin/group.php.
New
|
-
|
CVE-2024-48356
|
2024-10-31 02:35 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270
|
- |
|
-
|
-
|
MRCMS 3.1.2 contains a SQL injection vulnerability via the RID parameter in /admin/article/delete.do.
New
|
-
|
CVE-2024-48177
|
2024-10-31 02:35 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|