2211
|
- |
|
-
|
-
|
Path Traversal vulnerability in FULL. FULL Customer allows Path Traversal.This issue affects FULL Customer: from n/a through 3.1.25.
|
CWE-35
Path Traversal: '.../...//'
|
CVE-2024-54313
|
2024-12-14 00:15 |
2024-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2212
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ??????? ????? Persian Woocommerce SMS allows Reflected XSS.This issue affects Persian Woocommerce…
|
CWE-79
Cross-site Scripting
|
CVE-2024-54312
|
2024-12-14 00:15 |
2024-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2213
|
- |
|
-
|
-
|
Missing Authorization vulnerability in i.lychkov Mark New Posts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mark New Posts: from n/a through 7.5.1.
|
CWE-862
Missing Authorization
|
CVE-2024-54311
|
2024-12-14 00:15 |
2024-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2214
|
- |
|
-
|
-
|
Missing Authorization vulnerability in Aslam Khan Gouran Gou Manage My Account Menu allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Gou Manage My Account Menu: from…
|
CWE-862
Missing Authorization
|
CVE-2024-54310
|
2024-12-14 00:15 |
2024-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2215
|
- |
|
-
|
-
|
Insertion of Sensitive Information Into Sent Data vulnerability in wpdebuglog PostBox allows Retrieve Embedded Sensitive Data.This issue affects PostBox: from n/a through 1.0.4.
|
CWE-201
Insertion of Sensitive Information Into Sent Data
|
CVE-2024-54309
|
2024-12-14 00:15 |
2024-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2216
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CurrencyRate.today Cryptocurrency Price Widget allows Stored XSS.This issue affects Cryptocurrenc…
|
CWE-79
Cross-site Scripting
|
CVE-2024-54308
|
2024-12-14 00:15 |
2024-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2217
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in AIpost AIcomments allows Cross Site Request Forgery.This issue affects AIcomments: from n/a through 1.4.1.
|
CWE-352
Origin Validation Error
|
CVE-2024-54307
|
2024-12-14 00:15 |
2024-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2218
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in KCT AIKCT Engine Chatbot, ChatGPT, Gemini, GPT-4o Best AI Chatbot allows Cross Site Request Forgery.This issue affects AIKCT Engine Chatbot, ChatGPT…
|
CWE-352
Origin Validation Error
|
CVE-2024-54306
|
2024-12-14 00:15 |
2024-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2219
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in woocs J&T Express Malaysia allows Reflected XSS.This issue affects J&T Express Malaysia: from n/a…
|
CWE-79
Cross-site Scripting
|
CVE-2024-54305
|
2024-12-14 00:15 |
2024-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2220
|
- |
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hive Support Hive Support – WordPress Help Desk allows SQL Injection.This issue affects Hive Supp…
|
CWE-89
SQL Injection
|
CVE-2024-54304
|
2024-12-14 00:15 |
2024-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|