1831
|
6.1 |
MEDIUM
Network
|
elenazhyvohliad
|
ucat
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Elena Zhyvohliad uCAT – Next Story allows Reflected XSS.This issue affects uCAT – Next Sto…
|
CWE-79
Cross-site Scripting
|
CVE-2024-49663
|
2024-11-2 03:55 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1832
|
5.4 |
MEDIUM
Network
|
nervythemes
|
local_business_addons_for_elementor
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in NervyThemes Local Business Addons For Elementor allows Stored XSS.This issue affects Local…
|
CWE-79
Cross-site Scripting
|
CVE-2024-49667
|
2024-11-2 03:48 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1833
|
4.3 |
MEDIUM
Network
|
giuliopanda
|
bulk_images_optimizer
|
The Bulk images optimizer: Resize, optimize, convert to webp, rename … plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_configura…
|
CWE-862
Missing Authorization
|
CVE-2024-9361
|
2024-11-2 03:46 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1834
|
9.8 |
CRITICAL
Network
zte
|
wrtm326_firmware
|
The wireless router WRTM326 from SECOM does not properly validate a specific parameter. An unauthenticated remote attacker could execute arbitrary system commands by sending crafted requests.
|
CWE-78
OS Command
|
CVE-2024-10119
|
2024-11-2 03:40 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1835
|
- |
|
-
|
-
|
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=del&dataType=logo&dataTypeCN.
|
-
|
CVE-2024-35552
|
2024-11-2 03:35 |
2024-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1836
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
net: hns3: do not allow call hns3_nic_net_open repeatedly
hns3_nic_net_open() is not allowed to called repeatly, but there
is no …
|
-
|
CVE-2021-47400
|
2024-11-2 03:35 |
2024-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1837
|
- |
|
-
|
-
|
An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/DocumentTemplate/{GUID] XSS.
|
-
|
CVE-2024-33866
|
2024-11-2 03:35 |
2024-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1838
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix memory ordering between normal and ordered work functions
Ordered work functions aren't guaranteed to be handled by th…
|
-
|
CVE-2021-47189
|
2024-11-2 03:35 |
2024-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1839
|
- |
|
-
|
-
|
Vulnerability of input parameters being not strictly verified in the RSMC module.
Impact: Successful exploitation of this vulnerability may cause out-of-bounds write.
|
-
|
CVE-2023-52364
|
2024-11-2 03:35 |
2024-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1840
|
- |
|
-
|
-
|
Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated Ops and Viewers users to view all information on audit logs, including dag names and usernames they were not permi…
|
CWE-276
Incorrect Default Permissions
|
CVE-2024-26280
|
2024-11-2 03:35 |
2024-03-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|