2171
|
- |
|
-
|
-
|
The month name translation benaceur WordPress plugin before 2.3.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site …
|
-
|
CVE-2024-3634
|
2024-11-1 23:35 |
2024-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2172
|
- |
|
-
|
-
|
A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial …
|
-
|
CVE-2024-20312
|
2024-11-1 23:35 |
2024-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2173
|
8.8 |
HIGH
Network
|
tenda
|
o3_firmware
|
A vulnerability was found in Tenda O3 1.0.0.10(2478). It has been rated as critical. This issue affects the function fromSafeSetMacFilter of the file /goform/setMacFilterList. The manipulation of the…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-7152
|
2024-11-1 23:27 |
2024-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2174
|
5.4 |
MEDIUM
Network
|
purvabathe
|
simple_image_popup_shortcode
|
The Simple Image Popup Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sips_popup' shortcode in all versions up to, and including, 1.0 due to insufficien…
|
CWE-79
Cross-site Scripting
|
CVE-2024-5342
|
2024-11-1 23:27 |
2024-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2175
|
7.1 |
HIGH
Network
|
paloaltonetworks
|
pan-os
|
A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated GlobalProtect user to impersonate another GlobalProtect user. Active GlobalProtect …
|
CWE-863
Incorrect Authorization
|
CVE-2024-8691
|
2024-11-1 23:26 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2176
|
9.8 |
CRITICAL
Network
aa-team
|
wzone
|
Missing Authorization vulnerability in AA-Team WZone.This issue affects WZone: from n/a through 14.0.10.
|
CWE-862
Missing Authorization
|
CVE-2024-33545
|
2024-11-1 23:23 |
2024-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2177
|
6.5 |
MEDIUM
Network
mattermost
|
mattermost_desktop
|
Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather Chromium cookies or abuse other misconfigurations via remote/local access.
|
NVD-CWE-Other
|
CVE-2024-45835
|
2024-11-1 23:20 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2178
|
5.3 |
MEDIUM
Network
mattermost
|
mattermost_desktop
|
Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silently capture high-quality screenshots via JavaScript APIs.
|
NVD-CWE-noinfo
|
CVE-2024-39772
|
2024-11-1 23:20 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2179
|
7.5 |
HIGH
Network
gaizhenbiao
|
chuanhuchatgpt
|
An arbitrary file read vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240628 due to insufficient validation when loading prompt template files. An attacker can read any file that matche…
|
CWE-22
Path Traversal
|
CVE-2024-7962
|
2024-11-1 23:19 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2180
|
5.4 |
MEDIUM
Network
|
ysoft
|
safeq
|
Multiple Stored Cross-Site Scripting vulnerabilities were discovered in Y Soft SAFEQ 6 Build 53. Multiple fields in the YSoft SafeQ web application can be used to inject malicious inputs that, due to…
|
CWE-79
Cross-site Scripting
|
CVE-2022-23861
|
2024-11-1 23:19 |
2024-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|