|
313211
|
7.5 |
HIGH
Network
|
ruby-lang
|
rexml
|
REXML is an XML toolkit for Ruby. The REXML gem 3.3.2 has a DoS vulnerability when it parses an XML that has many entity expansions with SAX2 or pull parser API. The REXML gem 3.3.3 or later include …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2024-41946
|
2024-09-6 01:09 |
2024-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313212
|
7.2 |
HIGH
Network
|
dell
|
cloudlink
|
CloudLink, versions 7.1.x and 8.x, contain an Improper check or handling of Exceptional Conditions Vulnerability in Cluster Component. A highly privileged malicious user with remote access could pote…
|
NVD-CWE-Other
|
CVE-2024-38482
|
2024-09-6 01:04 |
2024-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313213
|
9.8 |
CRITICAL
Network
|
any1
|
neatvnc
|
server.c in Neat VNC (aka neatvnc) before 0.8.1 does not properly validate the security type, a related issue to CVE-2006-2369.
|
NVD-CWE-noinfo
|
CVE-2024-42458
|
2024-09-6 00:51 |
2024-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313214
|
5.4 |
MEDIUM
Network
|
metaphorcreations
|
ditty
|
The Ditty WordPress plugin before 3.1.45 does not sanitise and escape some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.
|
CWE-79
Cross-site Scripting
|
CVE-2024-6710
|
2024-09-6 00:30 |
2024-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313215
|
8.8 |
HIGH
Network
|
wpsoul
|
greenshift_query_addon
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wpsoul Greenshift Query and Meta Addon allows SQL Injection.This issue affects Greenshift Query a…
|
CWE-89
SQL Injection
|
CVE-2024-43942
|
2024-09-6 00:25 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313216
|
8.8 |
HIGH
Network
|
wpsoul
|
greenshift_woocommerce_addon
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wpsoul Greenshift Woocommerce Addon allows SQL Injection.This issue affects Greenshift Woocommerc…
|
CWE-89
SQL Injection
|
CVE-2024-43943
|
2024-09-6 00:10 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313217
|
8.8 |
HIGH
Network
|
wpmart
|
animated_number_counters
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sk. Abul Hasan Animated Number Counters allows PHP Local File Inclusion.This issue affects Animated Num…
|
CWE-22
Path Traversal
|
CVE-2024-43957
|
2024-09-5 23:49 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313218
|
5.4 |
MEDIUM
Network
|
alwindoss
|
akademy
|
A vulnerability was found in alwindoss akademy up to 35caccea888ed63d5489e211c99edff1f62efdba. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the f…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8407
|
2024-09-5 23:48 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313219
|
9.8 |
CRITICAL
Network
|
linksys
|
wrt54g_firmware
|
A vulnerability was found in Linksys WRT54G 4.21.5. It has been rated as critical. Affected by this issue is the function validate_services_port of the file /apply.cgi of the component POST Parameter…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-8408
|
2024-09-5 23:41 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313220
|
6.1 |
MEDIUM
Network
|
zzcms
|
zzcms
|
Cross Site Scripting vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via a crafted script to the pagename parameter of the admin/del.php component.
|
CWE-79
Cross-site Scripting
|
CVE-2024-44819
|
2024-09-5 23:40 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|