2061
|
8.8 |
HIGH
Network
|
priyabratasarkar
|
token_login
|
Authentication Bypass Using an Alternate Path or Channel vulnerability in Priyabrata Sarkar Token Login allows Authentication Bypass.This issue affects Token Login: from n/a through 1.0.3.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2024-50488
|
2024-10-31 22:19 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2062
|
9.8 |
CRITICAL
Network
tareqhasan
|
meetup
|
Authorization Bypass Through User-Controlled Key vulnerability in Meetup allows Privilege Escalation.This issue affects Meetup: from n/a through 0.1.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-50483
|
2024-10-31 22:12 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2063
|
9.8 |
CRITICAL
Network
mansurahamed
|
woocommerce_quote_calculator
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mansur Ahamed Woocommerce Quote Calculator allows Blind SQL Injection.This issue affects Woocomme…
|
CWE-89
SQL Injection
|
CVE-2024-50479
|
2024-10-31 22:02 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2064
|
9.8 |
CRITICAL
Network
codezips
|
hospital_appointment_system
|
A vulnerability, which was classified as critical, was found in Codezips Hospital Appointment System 1.0. This affects an unknown part of the file /loginAction.php. The manipulation of the argument U…
|
CWE-89
SQL Injection
|
CVE-2024-10449
|
2024-10-31 21:47 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2065
|
9.8 |
CRITICAL
Network
pymumu
|
smartdns
|
SmartDNS through 41 before 56d0332 allows an out-of-bounds write because of a stack-based buffer overflow in the _dns_encode_domain function in the dns.c file, via a crafted DNS request.
|
CWE-787
Out-of-bounds Write
|
CVE-2023-31470
|
2024-10-31 21:47 |
2023-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2066
|
9.0 |
CRITICAL
Network
|
apache intel cvat siemens debian sonicwall fedoraproject
|
log4j oneapi audio_development_kit datacenter_manager system_debugger secure_device_onboard sensor_solution_firmware_development_kit genomics_kernel_library system_studio c…
|
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC)…
|
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
|
CVE-2021-45046
|
2024-10-31 21:17 |
2021-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2067
|
6.1 |
MEDIUM
Network
|
rextheme
|
wp_vr
|
The WP VR WordPress plugin before 8.3.15 does not authorisation and CSRF in a function hooked to admin_init, allowing unauthenticated users to downgrade the plugin, thus leading to Reflected or Store…
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2023-6529
|
2024-10-31 20:45 |
2024-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2068
|
4.3 |
MEDIUM
Network
|
rextheme
|
wp_vr
|
The WP VR WordPress plugin before 8.3.0 does not have authorisation and CSRF checks in various AJAX actions, one in particular could allow any authenticated users, such as subscriber to update arbitr…
|
CWE-352 CWE-862
Origin Validation Error Missing Authorization
|
CVE-2023-1414
|
2024-10-31 20:45 |
2023-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2069
|
6.1 |
MEDIUM
Network
|
rextheme
|
wp_vr
|
The WP VR WordPress plugin before 8.2.9 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against h…
|
-
|
CVE-2023-1413
|
2024-10-31 20:45 |
2023-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2070
|
8.8 |
HIGH
Network
|
rextheme
|
wp_vr
|
Cross-Site Request Forgery (CSRF) vulnerability in Rextheme WP VR – 360 Panorama and Virtual Tour Builder For WordPress plugin <= 8.2.7 versions.
|
CWE-352
Origin Validation Error
|
CVE-2023-25708
|
2024-10-31 20:45 |
2023-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|