351
|
- |
|
-
|
-
|
HiveOS through 0.6-102@191212 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes trivial with Shodan.…
Update
|
-
|
CVE-2019-19754
|
2024-11-7 08:35 |
2024-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
352
|
- |
|
-
|
-
|
Using an AMP url with a canonical element, an attacker could have executed JavaScript from an opened bookmarked page. This vulnerability affects Firefox for iOS < 123.
Update
|
-
|
CVE-2024-26282
|
2024-11-7 08:35 |
2024-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
353
|
- |
|
-
|
-
|
A vulnerability was found in MonoCMS up to 20240528. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /monofiles/opensaved.php of the compon…
New
|
CWE-79 CWE-74
Cross-site Scripting Injection
|
CVE-2024-10928
|
2024-11-7 08:15 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
354
|
- |
|
-
|
-
|
A vulnerability was found in MonoCMS up to 20240528. It has been classified as problematic. Affected is an unknown function of the file /monofiles/account.php of the component Account Information Pag…
New
|
CWE-79 CWE-74
Cross-site Scripting Injection
|
CVE-2024-10927
|
2024-11-7 08:15 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
355
|
5.5 |
MEDIUM
Local
|
huawei
|
harmonyos
|
Vulnerability of input parameters not being verified in the HDC module
Impact: Successful exploitation of this vulnerability may affect availability.
New
|
NVD-CWE-noinfo
|
CVE-2024-51519
|
2024-11-7 08:15 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
356
|
7.5 |
HIGH
Network
huawei
|
harmonyos
|
Vulnerability of message types not being verified in the advanced messaging modul
Impact: Successful exploitation of this vulnerability may affect availability.
New
|
NVD-CWE-noinfo
|
CVE-2024-51518
|
2024-11-7 08:15 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
357
|
5.5 |
MEDIUM
Local
|
huawei
|
harmonyos
|
Vulnerability of improper memory access in the phone service module
Impact: Successful exploitation of this vulnerability may affect availability.
New
|
CWE-129
Improper Validation of Array Index
|
CVE-2024-51517
|
2024-11-7 08:15 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
358
|
8.8 |
HIGH
Network
|
darkmysite
|
darkmysite
|
Cross-Site Request Forgery (CSRF) vulnerability in DarkMySite DarkMySite – Advanced Dark Mode Plugin for WordPress darkmysite allows Cross Site Request Forgery.This issue affects DarkMySite – Advance…
Update
|
CWE-352
Origin Validation Error
|
CVE-2024-50466
|
2024-11-7 08:13 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
359
|
8.8 |
HIGH
Network
|
odude
|
crypto_tool
|
The Crypto plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.15. This is due to missing nonce validation in the 'crypto_connect_ajax_process::check'…
Update
|
CWE-352
Origin Validation Error
|
CVE-2024-9990
|
2024-11-7 08:11 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
360
|
9.8 |
CRITICAL
Network
hmplugin
|
aidwp
|
Missing Authorization vulnerability in HM Plugin WordPress Stripe Donation and Payment Plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Stri…
Update
|
CWE-862
Missing Authorization
|
CVE-2024-50459
|
2024-11-7 08:11 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|