2181
|
9.8 |
CRITICAL
Network
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ISDO Software Web Software allows SQL Injection.This issue affects Web Software: before 3.6.
|
CWE-89
SQL Injection
|
CVE-2024-10244
|
2024-12-19 23:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2182
|
- |
|
-
|
-
|
A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remote non-authenticated attacker to delete files on the system by sending a crafted…
|
CWE-305
Authentication Bypass by Primary Weakness
|
CVE-2021-26102
|
2024-12-19 23:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2183
|
- |
|
-
|
-
|
A vulnerability was found in itsourcecode Vehicle Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /billaction.php. The manipulation of the …
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2024-12783
|
2024-12-19 22:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2184
|
- |
|
-
|
-
|
A use after free in Fortinet FortiManager, FortiAnalyzer allows attacker to execute unauthorized code or commands via <insert attack vector here>
|
CWE-416
Use After Free
|
CVE-2021-32589
|
2024-12-19 22:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2185
|
- |
|
-
|
-
|
PVH guests have their ACPI tables constructed by the toolstack. The
construction involves building the tables in local memory, which are
then copied into guest memory. While actually used parts of …
|
-
|
CVE-2024-45819
|
2024-12-19 21:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2186
|
- |
|
-
|
-
|
The hypervisor contains code to accelerate VGA memory accesses for HVM
guests, when the (virtual) VGA is in "standard" mode. Locking involved
there has an unusual discipline, leaving a lock acquired…
|
-
|
CVE-2024-45818
|
2024-12-19 21:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2187
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Agency Dominion Fusion allows Stored XSS.This issue affects Fusion: from n/a through 1.6.1.
|
CWE-79
Cross-site Scripting
|
CVE-2024-37962
|
2024-12-19 21:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2188
|
9.6 |
CRITICAL
Network
|
-
|
-
|
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘a-0-o-search_fiel…
|
CWE-79
Cross-site Scripting
|
CVE-2024-12626
|
2024-12-19 21:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2189
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_install_plugin' function in all versions up to, …
|
CWE-862
Missing Authorization
|
CVE-2024-12331
|
2024-12-19 21:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2190
|
- |
|
-
|
-
|
An OS command injection (CWE-78) vulnerability in FortiWAN version 4.5.7 and below Command Line Interface may allow a local, authenticated and unprivileged attacker to escalate their privileges to ro…
|
CWE-78
OS Command
|
CVE-2021-26115
|
2024-12-19 20:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|