1861
|
- |
|
-
|
-
|
In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the auto-generation function was identified. Reported by Karol Wi?sek.
|
-
|
CVE-2024-10314
|
2024-11-12 22:55 |
2024-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1862
|
- |
|
-
|
-
|
A flaw was found in moodle. Insufficient sanitizing of data when performing a restore could result in a cross-site scripting (XSS) risk from malicious backup files.
|
-
|
CVE-2024-43437
|
2024-11-12 22:55 |
2024-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1863
|
- |
|
-
|
-
|
A flaw was found in moodle. Some hidden user profile fields are visible in gradebook reports, which could result in users without the "view hidden user fields" capability having access to the informa…
|
-
|
CVE-2024-43429
|
2024-11-12 22:55 |
2024-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1864
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Webopac from Grand Vice info has Stored Cross-site Scripting vulnerability. Remote attackers with regular privileges can inject arbitrary JavaScript code into the server. When users visit the comprom…
|
CWE-79
Cross-site Scripting
|
CVE-2024-11021
|
2024-11-12 22:55 |
2024-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1865
|
9.8 |
CRITICAL
Network
-
|
-
|
Webopac from Grand Vice info has a SQL Injection vulnerability, allowing unauthenticated remote attacks to inject arbitrary SQL commands to read, modify, and delete database contents.
|
CWE-89
SQL Injection
|
CVE-2024-11020
|
2024-11-12 22:55 |
2024-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1866
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Webopac from Grand Vice info has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript code in the user's browser through phishing …
|
CWE-79
Cross-site Scripting
|
CVE-2024-11019
|
2024-11-12 22:55 |
2024-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1867
|
9.8 |
CRITICAL
Network
-
|
-
|
Webopac from Grand Vice info does not properly validate uploaded file types, allowing unauthenticated remote attackers to upload and execute webshells, which could lead to arbitrary code execution on…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-11018
|
2024-11-12 22:55 |
2024-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1868
|
8.8 |
HIGH
Network
|
-
|
-
|
Webopac from Grand Vice info does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload and execute webshells, which could lead to arbitrary code exec…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-11017
|
2024-11-12 22:55 |
2024-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1869
|
- |
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Richteam Share Buttons – Social Media allows Blind SQL Injection.This issue affects Share Buttons…
|
CWE-89
SQL Injection
|
CVE-2024-51845
|
2024-11-12 22:55 |
2024-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1870
|
- |
|
-
|
-
|
Unrestricted Upload of File with Dangerous Type vulnerability in Dang Ngoc Binh Audio Record allows Upload a Web Shell to a Web Server.This issue affects Audio Record: from n/a through 1.0.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-51792
|
2024-11-12 22:55 |
2024-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|