2351
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Broadcast plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'do_check' parameter in all versions up to, and including, 51.01 due to insufficient input sanitization and …
|
CWE-79
Cross-site Scripting
|
CVE-2024-11379
|
2024-12-6 14:15 |
2024-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2352
|
4.4 |
MEDIUM
Network
|
-
|
-
|
The Video Gallery – Best WordPress YouTube Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.1 due to insufficient…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9769
|
2024-12-6 13:15 |
2024-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2353
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Flixita theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.0.82 due to insufficient input sanitization and output e…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10836
|
2024-12-6 13:15 |
2024-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2354
|
7.2 |
HIGH
Network
|
-
|
-
|
The Video Gallery – Best WordPress YouTube Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the orderby parameter in all versions up to, and including, 2.4.2 due to i…
|
CWE-89
SQL Injection
|
CVE-2024-10247
|
2024-12-6 13:15 |
2024-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2355
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Microsoft Edge (Chromium-based) Spoofing Vulnerability
|
CWE-449
The UI Performs the Wrong Action
|
CVE-2024-49041
|
2024-12-6 11:15 |
2024-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2356
|
- |
|
-
|
-
|
In OpenBSD 7.4 before errata 014, vmm(4) did not restore GDTR limits properly on Intel (VMX) CPUs.
|
-
|
CVE-2024-11149
|
2024-12-6 11:15 |
2024-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2357
|
- |
|
-
|
-
|
Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured.
|
-
|
CVE-2024-6219
|
2024-12-6 09:15 |
2024-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2358
|
- |
|
-
|
-
|
Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store.
|
-
|
CVE-2024-6156
|
2024-12-6 09:15 |
2024-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2359
|
- |
|
-
|
-
|
path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. The regular expression…
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2024-52798
|
2024-12-6 08:15 |
2024-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2360
|
- |
|
-
|
-
|
Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via the nav2_amcl p…
|
-
|
CVE-2024-30962
|
2024-12-6 08:15 |
2024-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|