551
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Basic Information Disclosure in all versions up to, and including, 4.5 via the CF7_get_post_var shortcode. This makes…
New
|
CWE-200
Information Exposure
|
CVE-2024-10084
|
2024-11-7 03:17 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
552
|
- |
|
-
|
-
|
A maliciously crafted binary file when downloaded could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to an untrusted search path being utilized in the VRED Design application. Exploita…
New
|
-
|
CVE-2024-7995
|
2024-11-7 03:17 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
553
|
- |
|
-
|
-
|
The AuthKit library for Remix provides convenient helpers for authentication and session management using WorkOS & AuthKit with Remix. In affected versions refresh tokens are logged to the console wh…
New
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2024-51753
|
2024-11-7 03:17 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
554
|
- |
|
-
|
-
|
Wasmtime is a fast and secure runtime for WebAssembly. Wasmtime's filesystem sandbox implementation on Windows blocks access to special device filenames such as "COM1", "COM2", "LPT0", "LPT1", and so…
New
|
CWE-184 CWE-67
Incomplete Blacklist
|
CVE-2024-51745
|
2024-11-7 03:17 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
555
|
- |
|
-
|
-
|
The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & AuthKit with Next.js. In affected versions refresh tokens are logged to the consol…
New
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2024-51752
|
2024-11-7 03:17 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
556
|
- |
|
-
|
-
|
Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. gitsign may select the wrong Rekor entry to use during online verification when multiple entries are …
New
|
CWE-706
Use of Incorrectly-Resolved Name or Reference
|
CVE-2024-51746
|
2024-11-7 03:17 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
557
|
- |
|
-
|
-
|
Combodo iTop is a simple, web based IT Service Management tool. This vulnerability can be used to create HTTP requests on behalf of the server, from a low privileged user. The user portal form manage…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-51740
|
2024-11-7 03:17 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
558
|
- |
|
-
|
-
|
Osmedeus is a Workflow Engine for Offensive Security. Cross-site Scripting (XSS) occurs on the Osmedues web server when viewing results from the workflow, allowing commands to be executed on the serv…
New
|
CWE-79 CWE-80
Cross-site Scripting Basic XSS
|
CVE-2024-51735
|
2024-11-7 03:17 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
559
|
- |
|
-
|
-
|
OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.2 contain a vulnerability that allows an attacker that has gained temporary con…
New
|
CWE-620
Unverified Password Change
|
CVE-2024-51493
|
2024-11-7 03:17 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
560
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 allows an attacker to reset the administrator's password. This critical security flaw can result in unauthorized access to the platform…
New
|
-
|
CVE-2024-51382
|
2024-11-7 03:17 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|