2621
|
6.1 |
MEDIUM
Network
|
julianweinert
|
cslider
|
Cross-Site Request Forgery (CSRF) vulnerability in Julian Weinert // cs&m cSlider allows Stored XSS.This issue affects cSlider: from n/a through 2.4.2.
|
CWE-352
Origin Validation Error
|
CVE-2024-49221
|
2024-11-7 05:54 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2622
|
9.8 |
CRITICAL
Network
madirisalmanaashish
|
adding_drop_down_roles_in_registration
|
Incorrect Privilege Assignment vulnerability in Madiri Salman Aashish Adding drop down roles in registration allows Privilege Escalation.This issue affects Adding drop down roles in registration: fro…
|
NVD-CWE-Other
|
CVE-2024-49217
|
2024-11-7 05:53 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2623
|
8.8 |
HIGH
Network
|
themexpo
|
rs-members
|
Incorrect Privilege Assignment vulnerability in themexpo RS-Members allows Privilege Escalation.This issue affects RS-Members: from n/a through 1.0.3.
|
NVD-CWE-Other
|
CVE-2024-49219
|
2024-11-7 05:45 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2624
|
6.1 |
MEDIUM
Network
|
cookie-scanner
|
cookie_scanner
|
Cross-Site Request Forgery (CSRF) vulnerability in Cookie Scanner – Nikel Schubert Cookie Scanner allows Stored XSS.This issue affects Cookie Scanner: from n/a through 1.1.
|
CWE-352
Origin Validation Error
|
CVE-2024-49220
|
2024-11-7 05:41 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2625
|
6.1 |
MEDIUM
Network
|
arifnezami
|
better_author_bio
|
Cross-Site Request Forgery (CSRF) vulnerability in Arif Nezami Better Author Bio allows Cross-Site Scripting (XSS).This issue affects Better Author Bio: from n/a through 2.7.10.11.
|
CWE-352
Origin Validation Error
|
CVE-2024-49229
|
2024-11-7 05:40 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2626
|
6.5 |
MEDIUM
Network
|
ibm
|
db2
|
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service, under specific configurations, as the server may crash when using a specia…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2024-31880
|
2024-11-7 05:39 |
2024-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2627
|
- |
|
-
|
-
|
langflow <=1.0.18 is vulnerable to Remote Code Execution (RCE) as any component provided the code functionality and the components run on the local machine rather than in a sandbox.
|
-
|
CVE-2024-48061
|
2024-11-7 05:35 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2628
|
- |
|
-
|
-
|
In gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The reason is that within the save_url_to_cache function, there are no restrictions o…
|
-
|
CVE-2024-48052
|
2024-11-7 05:35 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2629
|
- |
|
-
|
-
|
An issue was discovered in Infinera hiT 7300 5.60.50. Hidden functionality in the web interface allows a remote authenticated attacker to access reserved information by accessing undocumented web app…
|
-
|
CVE-2024-28808
|
2024-11-7 05:35 |
2024-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2630
|
- |
|
-
|
-
|
A vulnerability has been discovered in all versions of Smartplay headunits, which are widely used in Suzuki and Toyota cars. This misconfiguration can lead to information disclosure, leaking sensitiv…
|
-
|
CVE-2024-39339
|
2024-11-7 05:35 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|