1121
|
7.8 |
HIGH
Local
|
-
|
-
|
PDFL SDK versions 21.0.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issu…
|
-
|
CVE-2024-49513
|
2024-12-17 02:15 |
2024-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1122
|
- |
|
-
|
-
|
Missing Authorization vulnerability in David Cramer Caldera SMTP Mailer.This issue affects Caldera SMTP Mailer: from n/a through 1.0.1.
|
CWE-862
Missing Authorization
|
CVE-2024-56003
|
2024-12-17 01:15 |
2024-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1123
|
- |
|
-
|
-
|
Missing Authorization vulnerability in Marco Giannini XML Multilanguage Sitemap Generator.This issue affects XML Multilanguage Sitemap Generator: from n/a through 2.0.6.
|
CWE-862
Missing Authorization
|
CVE-2024-55999
|
2024-12-17 01:15 |
2024-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1124
|
- |
|
-
|
-
|
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Spider-themes EazyDocs.This issue affects EazyDocs: from n/a through 2.5.5.
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2024-54376
|
2024-12-17 01:15 |
2024-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1125
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.10.
|
CWE-352
Origin Validation Error
|
CVE-2024-54357
|
2024-12-17 01:15 |
2024-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1126
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YayCommerce Brand allows Stored XSS.This issue affects Brand: from n/a through 1.1.6.
|
CWE-79
Cross-site Scripting
|
CVE-2024-54348
|
2024-12-17 01:15 |
2024-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1127
|
- |
|
-
|
-
|
Unrestricted Upload of File with Dangerous Type vulnerability in SeedProd LLC SeedProd Pro allows Upload a Web Shell to a Web Server.This issue affects SeedProd Pro: from n/a through 6.18.10.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-54285
|
2024-12-17 01:15 |
2024-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1128
|
- |
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SeedProd LLC SeedProd Pro allows SQL Injection.This issue affects SeedProd Pro: from n/a through …
|
CWE-89
SQL Injection
|
CVE-2024-54284
|
2024-12-17 01:15 |
2024-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1129
|
- |
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SeedProd LLC SeedProd Pro allows SQL Injection.This issue affects SeedProd Pro: from n/a through …
|
CWE-89
SQL Injection
|
CVE-2024-54283
|
2024-12-17 01:15 |
2024-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1130
|
- |
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design WPBookit allows SQL Injection.This issue affects WPBookit: from n/a through 1.6.0.
|
CWE-89
SQL Injection
|
CVE-2024-54280
|
2024-12-17 01:15 |
2024-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|