1321
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Boston University (IS&T) BU Slideshow allows Stored XSS.This issue affects BU Slideshow: f…
|
CWE-79
Cross-site Scripting
|
CVE-2024-52351
|
2024-11-12 22:55 |
2024-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1322
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CRM 2go allows DOM-Based XSS.This issue affects CRM 2go: from n/a through 1.0.
|
-
|
CVE-2024-52350
|
2024-11-12 22:55 |
2024-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1323
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Webopac from Grand Vice info has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript code in the user's browser through phishing …
|
CWE-79
Cross-site Scripting
|
CVE-2024-11019
|
2024-11-12 22:55 |
2024-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1324
|
9.8 |
CRITICAL
Network
-
|
-
|
Webopac from Grand Vice info does not properly validate uploaded file types, allowing unauthenticated remote attackers to upload and execute webshells, which could lead to arbitrary code execution on…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-11018
|
2024-11-12 22:55 |
2024-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1325
|
8.8 |
HIGH
Network
|
-
|
-
|
Webopac from Grand Vice info does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload and execute webshells, which could lead to arbitrary code exec…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-11017
|
2024-11-12 22:55 |
2024-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1326
|
9.8 |
CRITICAL
Network
-
|
-
|
Webopac from Grand Vice info has a SQL Injection vulnerability, allowing unauthenticated remote attacks to inject arbitrary SQL commands to read, modify, and delete database contents.
|
-
|
CVE-2024-11016
|
2024-11-12 22:55 |
2024-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1327
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Cyberchimps Responsive Addons for Elementor allows DOM-Based XSS.This issue affects Respon…
|
CWE-79
Cross-site Scripting
|
CVE-2024-52358
|
2024-11-12 22:55 |
2024-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1328
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in LIQUID DESIGN Ltd. LIQUID BLOCKS allows Stored XSS.This issue affects LIQUID BLOCKS: from …
|
CWE-79
Cross-site Scripting
|
CVE-2024-52357
|
2024-11-12 22:55 |
2024-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1329
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Webangon The Pack Elementor addons allows Stored XSS.This issue affects The Pack Elementor…
|
CWE-79
Cross-site Scripting
|
CVE-2024-52356
|
2024-11-12 22:55 |
2024-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1330
|
- |
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ehues Gboy Custom Google Map allows Blind SQL Injection.This issue affects Gboy Custom Google Map…
|
CWE-89
SQL Injection
|
CVE-2024-51882
|
2024-11-12 22:55 |
2024-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|