|
313211
|
5.4 |
MEDIUM
Network
|
friendica
|
friendica
|
Friendica 2024.03 is vulnerable to Cross Site Scripting (XSS) in settings/profile via the homepage, xmpp, and matrix parameters.
|
CWE-79
Cross-site Scripting
|
CVE-2024-39094
|
2024-08-21 22:31 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313212
|
7.5 |
HIGH
Network
|
keyfactor
|
command
|
Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in information disclosure.
|
CWE-89
SQL Injection
|
CVE-2024-34458
|
2024-08-21 22:31 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313213
|
7.5 |
HIGH
Network
|
keyfactor
|
aws_orchestrator
|
Keyfactor AWS Orchestrator through 2.0 allows Information Disclosure.
|
NVD-CWE-noinfo
|
CVE-2024-42006
|
2024-08-21 22:26 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313214
|
8.8 |
HIGH
Network
|
pligg
|
pligg_cms
|
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=clearall
|
CWE-352
Origin Validation Error
|
CVE-2024-42603
|
2024-08-21 22:21 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313215
|
8.8 |
HIGH
Network
|
pligg
|
pligg_cms
|
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=avatars
|
CWE-352
Origin Validation Error
|
CVE-2024-42609
|
2024-08-21 22:12 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313216
|
8.8 |
HIGH
Network
|
pligg
|
pligg_cms
|
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=database
|
CWE-352
Origin Validation Error
|
CVE-2024-42607
|
2024-08-21 22:12 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313217
|
8.8 |
HIGH
Network
|
pligg
|
pligg_cms
|
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_log.php?clear=1
|
CWE-352
Origin Validation Error
|
CVE-2024-42606
|
2024-08-21 22:12 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313218
|
8.8 |
HIGH
Network
|
pligg
|
pligg_cms
|
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/edit_page.php?link_id=1
|
CWE-352
Origin Validation Error
|
CVE-2024-42605
|
2024-08-21 22:12 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313219
|
8.8 |
HIGH
Network
|
pligg
|
pligg_cms
|
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_widgets.php?action=install&widget=akismet
|
CWE-352
Origin Validation Error
|
CVE-2024-42613
|
2024-08-21 22:11 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313220
|
8.8 |
HIGH
Network
|
pligg
|
pligg_cms
|
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/admin_page.php?link_id=1&mode=delete
|
CWE-352
Origin Validation Error
|
CVE-2024-42611
|
2024-08-21 22:11 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|