1021
|
4.3 |
MEDIUM
Network
|
sinaextra
|
sina_extension_for_elementor
|
The Sina Extension for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.7 via the render function in widgets/advanced/sina-moda…
Update
|
CWE-200
Information Exposure
|
CVE-2024-9540
|
2024-10-31 05:56 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1022
|
6.1 |
MEDIUM
Network
|
woo
|
product_vendors
|
The Product Vendors is vulnerable to Reflected Cross-Site Scripting via the 'vendor_description' parameter in versions up to, and including, 2.0.35 due to insufficient input sanitization and output e…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2017-20193
|
2024-10-31 05:46 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1023
|
4.3 |
MEDIUM
Network
|
agnai
|
agnai
|
Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions prior to 1.0.330 permits attackers to upload image files at attacker-chosen loca…
Update
|
CWE-22
Path Traversal
|
CVE-2024-47171
|
2024-10-31 05:46 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1024
|
4.8 |
MEDIUM
Network
|
netgate
|
pfsense
|
A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $pconfig variable at interfaces_groups_e…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-46538
|
2024-10-31 05:45 |
2024-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1025
|
7.5 |
HIGH
Network
apple
|
xcode
|
This issue was addressed with improved permissions checking. This issue is fixed in Xcode 16. An app may be able to inherit Xcode permissions and access user data.
Update
|
NVD-CWE-noinfo
|
CVE-2024-44228
|
2024-10-31 05:35 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1026
|
- |
|
-
|
-
|
Ironman PowerShell Universal 5.x before 5.0.12 allows an authenticated attacker to elevate their privileges and view job information.
Update
|
-
|
CVE-2024-50616
|
2024-10-31 05:35 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1027
|
- |
|
-
|
-
|
TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/digit, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterRef.
Update
|
-
|
CVE-2024-50615
|
2024-10-31 05:35 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1028
|
- |
|
-
|
-
|
TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/16, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterRef.
Update
|
-
|
CVE-2024-50614
|
2024-10-31 05:35 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1029
|
- |
|
-
|
-
|
libsndfile through 1.2.2 has an ogg_vorbis.c vorbis_analysis_wrote out-of-bounds read.
Update
|
-
|
CVE-2024-50612
|
2024-10-31 05:35 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1030
|
- |
|
-
|
-
|
AIML Chatbot 1.0 (fixed in 2.0) is vulnerable to Cross Site Scripting (XSS). The vulnerability is exploited through the message input field, where attackers can inject malicious HTML or JavaScript co…
Update
|
-
|
CVE-2024-48396
|
2024-10-31 05:35 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|