2581
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The ScanCircle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'scancircle' shortcode in all versions up to, and including, 2.9.2 due to insufficient input sanitiza…
|
CWE-79
Cross-site Scripting
|
CVE-2024-11439
|
2024-12-18 12:15 |
2024-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2582
|
- |
|
-
|
-
|
File upload logic is flawed vulnerability in Apache Struts.
This issue affects Apache Struts: from 2.0.0 before 6.4.0.
Users are recommended to upgrade to version 6.4.0 and migrate to the new file…
|
-
|
CVE-2024-53677
|
2024-12-18 10:15 |
2024-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2583
|
7.5 |
HIGH
Network
|
-
|
-
|
A flaw was found in Open Cluster Management (OCM) when a user has access to the worker nodes which contain the cluster-manager or klusterlet deployments. The cluster-manager deployment uses a service…
|
CWE-501
Trust Boundary Violation
|
CVE-2024-9779
|
2024-12-18 08:15 |
2024-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2584
|
5.7 |
MEDIUM
Adjacent
|
-
|
-
|
A vulnerability was found in Keycloak. The environment option `KC_CACHE_EMBEDDED_MTLS_ENABLED` does not work and the JGroups replication configuration is always used in plain text which can allow an …
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2024-10973
|
2024-12-18 08:15 |
2024-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2585
|
- |
|
-
|
-
|
LDAP Account Manager (LAM) is a php webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In affected versions LAM does not properly sanitize configuration…
|
CWE-610
Externally Controlled Reference to a Resource in Another Sphere
|
CVE-2024-52792
|
2024-12-18 07:15 |
2024-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2586
|
- |
|
-
|
-
|
Cross-site scripting (XSS) vulnerability in the edit Service Access Policy page in Liferay Portal 7.0.0 through 7.4.3.87, and Liferay DXP 7.4 GA through update 87, 7.3 GA through update 29, and older…
|
CWE-79
Cross-site Scripting
|
CVE-2023-37940
|
2024-12-18 07:15 |
2024-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2587
|
- |
|
-
|
-
|
Phpgurukul Online Birth Certificate System 1.0 suffers from insufficient password requirements which can lead to unauthorized access to user accounts.
|
-
|
CVE-2024-55057
|
2024-12-18 07:15 |
2024-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2588
|
- |
|
-
|
-
|
A stored cross-site scripting (XSS) vulnerability was identified in Phpgurukul Online Birth Certificate System 1.0 in /user/certificate-form.php via the full name field.
|
-
|
CVE-2024-55056
|
2024-12-18 07:15 |
2024-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2589
|
- |
|
-
|
-
|
An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to docu…
|
-
|
CVE-2024-12539
|
2024-12-18 06:15 |
2024-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2590
|
- |
|
-
|
-
|
Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.1.0 through 7.4.3.38, and Liferay DXP 7.4 GA through update 38, 7.3 GA through update 36, 7.2 GA through fix pack 20 and 7.1 GA …
|
CWE-79
Cross-site Scripting
|
CVE-2024-11993
|
2024-12-18 06:15 |
2024-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|