2141
|
- |
|
-
|
-
|
Keyfactor Command before 12.5.0 has Incorrect Access Control: access tokens are over permissioned, aka 64099. The fixed versions are 11.5.1.1, 11.5.2.1, 11.5.3.1, 11.5.4.5, 11.5.6.1, 11.6.0, 12.2.0.1…
|
-
|
CVE-2024-49202
|
2024-12-21 09:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2142
|
- |
|
-
|
-
|
Keyfactor Remote File Orchestrator (aka remote-file-orchestrator) 2.8 before 2.8.1 allows Information Disclosure: sensitive information could be exposed at the debug logging level.
|
-
|
CVE-2024-49201
|
2024-12-21 09:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2143
|
- |
|
-
|
-
|
Rhymix 2.1.19 is vulnerable to Server-Side Request Forgery (SSRF) in the background import data function.
|
-
|
CVE-2024-55089
|
2024-12-21 09:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2144
|
- |
|
-
|
-
|
GetSimple CMS CE 3.3.19 is vulnerable to Server-Side Request Forgery (SSRF) in the backend plugin module.
|
-
|
CVE-2024-55088
|
2024-12-21 09:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2145
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Feedify – Web Push Notifications plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'platform', 'phone', 'email', and 'store_url' parameters. in all versions up to, and …
|
CWE-79
Cross-site Scripting
|
CVE-2024-11811
|
2024-12-21 08:15 |
2024-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2146
|
- |
|
-
|
-
|
A vulnerability classified as problematic was found in Emlog Pro up to 2.4.1. Affected by this vulnerability is an unknown functionality in the library /include/lib/common.php. The manipulation of th…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2024-12845
|
2024-12-21 07:15 |
2024-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2147
|
- |
|
-
|
-
|
grist-core is a spreadsheet hosting server. A user visiting a malicious document and clicking on a link in a HyperLink cell using a control modifier (meaning for example Ctrl+click) could have their …
|
CWE-79
Cross-site Scripting
|
CVE-2024-56359
|
2024-12-21 06:15 |
2024-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2148
|
- |
|
-
|
-
|
grist-core is a spreadsheet hosting server. A user visiting a malicious document and previewing an attachment could have their account compromised, because JavaScript in an SVG file would be evaluate…
|
CWE-79
Cross-site Scripting
|
CVE-2024-56358
|
2024-12-21 06:15 |
2024-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2149
|
- |
|
-
|
-
|
grist-core is a spreadsheet hosting server. A user visiting a malicious document or submitting a malicious form could have their account compromised, because it was possible to use the `javascript:` …
|
CWE-79
Cross-site Scripting
|
CVE-2024-56357
|
2024-12-21 06:15 |
2024-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2150
|
- |
|
-
|
-
|
There is a cross-site scripting vulnerability in the
management console of Absolute Secure Access prior to version 13.52. Attackers
with system administrator permissions can interfere with another sy…
|
-
|
CVE-2024-40875
|
2024-12-21 06:15 |
2024-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|