2131
|
5.3 |
MEDIUM
Network
hcltech
|
sametime
|
HCL Sametime is impacted by misconfigured security related HTTP headers. It was identified that some HTTP headers were missing on web service responses. This will lead to less secure browser default …
|
NVD-CWE-noinfo
|
CVE-2024-30122
|
2024-11-7 07:33 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2132
|
4.9 |
MEDIUM
Network
|
pimcore
|
pimcore
|
Pimcore is an open source data and experience management platform. When a PortalUserObject is connected to a PimcoreUser and "Use Pimcore Backend Password" is set to true, the change password functio…
|
NVD-CWE-Other
|
CVE-2024-49370
|
2024-11-7 07:31 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2133
|
8.8 |
HIGH
Network
|
vitaliibryl
|
switch_user
|
Authentication Bypass Using an Alternate Path or Channel vulnerability in Vitalii Bryl iBryl Switch User allows Authentication Bypass.This issue affects iBryl Switch User: from n/a through 1.0.1.
|
NVD-CWE-Other
|
CVE-2024-49675
|
2024-11-7 07:24 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2134
|
5.4 |
MEDIUM
Network
|
migaweb
|
custom_post_type_templates_for_elementor
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Gangolf Custom post type templates for Elementor allows Stored XSS.This issue affe…
|
CWE-79
Cross-site Scripting
|
CVE-2024-51683
|
2024-11-7 07:12 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2135
|
5.4 |
MEDIUM
Network
|
hasthemes
|
ht_builder
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in HasThemes HT Builder – WordPress Theme Builder for Elementor allows Stored XSS.This issue …
|
CWE-79
Cross-site Scripting
|
CVE-2024-51682
|
2024-11-7 07:12 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2136
|
5.4 |
MEDIUM
Network
|
coderevolution
|
wp_pocket_urls
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CodeRevolution WP Pocket URLs allows Stored XSS.This issue affects WP Pocket URLs: from n/…
|
CWE-79
Cross-site Scripting
|
CVE-2024-51681
|
2024-11-7 07:11 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2137
|
5.4 |
MEDIUM
Network
|
crestaproject
|
cresta_addons_for_elementor
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CrestaProject – Rizzo Andrea Cresta Addons for Elementor allows Stored XSS.This issue affe…
|
CWE-79
Cross-site Scripting
|
CVE-2024-51680
|
2024-11-7 07:10 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2138
|
5.4 |
MEDIUM
Network
|
timelord
|
elo_rating_shortcode
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Marcel Pol Elo Rating Shortcode allows Stored XSS.This issue affects Elo Rating Shortcode:…
|
CWE-79
Cross-site Scripting
|
CVE-2024-51678
|
2024-11-7 07:10 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2139
|
5.4 |
MEDIUM
Network
|
webberzone
|
knowledge_base
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WebberZone Knowledge Base allows Stored XSS.This issue affects Knowledge Base: from n/a th…
|
CWE-79
Cross-site Scripting
|
CVE-2024-51677
|
2024-11-7 07:10 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2140
|
8.8 |
HIGH
Network
|
mansurahamed
|
woocommerce_quote_calculator
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mansur Ahamed Woocommerce Quote Calculator allows Blind SQL Injection.This issue affects Woocomme…
|
CWE-89
SQL Injection
|
CVE-2024-51626
|
2024-11-7 07:10 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|