|
314081
|
5.4 |
MEDIUM
Network
|
gitlab
|
gitlab
|
A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 prior 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2. When view…
|
CWE-79
Cross-site Scripting
|
CVE-2024-4207
|
2024-09-18 21:41 |
2024-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314082
|
8.8 |
HIGH
Network
|
google microsoft
|
chrome edge_chromium
|
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
|
CWE-787
Out-of-bounds Write
|
CVE-2024-7965
|
2024-09-18 21:40 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314083
|
8.8 |
HIGH
Network
|
redhat
|
openshift_data_science openshift_ai
|
A vulnerability was found in OpenShift AI that allows for authentication bypass and privilege escalation across models within the same namespace. When deploying AI models, the UI provides the option …
|
NVD-CWE-Other
|
CVE-2024-7557
|
2024-09-18 16:15 |
2024-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314084
|
6.7 |
MEDIUM
Local
|
microsoft
|
windows_10_1507 windows_10_1809 windows_server_2019 windows_server_2022 windows_11_21h2 windows_10_21h2 windows_11_22h2 windows_10_22h2 windows_11_23h2 windows_server_2022_…
|
Summary:
Microsoft was notified that an elevation of privilege vulnerability exists in Windows based systems supporting Virtualization Based Security (VBS), including a subset of Azure Virtual Machin…
|
NVD-CWE-Other
|
CVE-2024-21302
|
2024-09-18 09:15 |
2024-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314085
|
7.5 |
HIGH
Network
|
containers
|
aardvark-dns
|
A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP DNS queries. An attacker can exploit this flaw by keeping a TCP connection open…
|
NVD-CWE-noinfo
|
CVE-2024-8418
|
2024-09-18 05:15 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314086
|
4.3 |
MEDIUM
Network
|
imagerecycle
|
imagerecycle_pdf_\&_image_compression
|
The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.14. This is due to missing or incorrect nonce valid…
|
CWE-352
Origin Validation Error
|
CVE-2024-8120
|
2024-09-18 05:07 |
2024-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314087
|
4.8 |
MEDIUM
Network
|
cleversoft
|
clever_addons_for_elementor
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CleverSoft Clever Addons for Elementor allows Stored XSS.This issue affects Clever Addons …
|
CWE-79
Cross-site Scripting
|
CVE-2024-43324
|
2024-09-18 05:04 |
2024-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314088
|
6.1 |
MEDIUM
Network
|
orbisius
|
child_theme_creator
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Svetoslav Marinov (Slavi) Child Theme Creator allows Reflected XSS.This issue affects Chil…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43276
|
2024-09-18 05:00 |
2024-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314089
|
5.4 |
MEDIUM
Network
|
cpothemes
|
allegiant
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Chill Allegiant allegiant allows Stored XSS.This issue affects Allegiant: from n/a thro…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43329
|
2024-09-18 04:59 |
2024-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314090
|
6.1 |
MEDIUM
Network
|
wpbeaveraddons
|
powerpack_lite_for_beaver_builder
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in IdeaBox Creations PowerPack for Beaver Builder allows Reflected XSS.This issue affects Pow…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43330
|
2024-09-18 04:53 |
2024-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|