|
313371
|
8.8 |
HIGH
Network
|
progress
|
whatsup_gold
|
In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an authenticated low-privileged attacker to achieve privilege escalation by modifying a privileged user's passw…
|
CWE-89
SQL Injection
|
CVE-2024-6672
|
2024-09-4 23:23 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313372
|
5.4 |
MEDIUM
Network
|
jpatokal
|
openflights
|
openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/trip.php
|
CWE-79
Cross-site Scripting
|
CVE-2024-41345
|
2024-09-4 23:17 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313373
|
4.3 |
MEDIUM
Network
|
dineshkarki
|
wp_armour_extended
|
Cross-Site Request Forgery (CSRF) vulnerability in Dinesh Karki WP Armour Extended.This issue affects WP Armour Extended: from n/a through 1.26.
|
CWE-352
Origin Validation Error
|
CVE-2024-43947
|
2024-09-4 23:16 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313374
|
- |
|
-
|
-
|
Rejected reason: Invalid security issue.
|
-
|
CVE-2024-6716
|
2024-09-4 23:15 |
2024-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313375
|
6.1 |
MEDIUM
Network
|
magic-post-thumbnail
|
magic_post_thumbnail
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Magic Post Thumbnail allows Reflected XSS.This issue affects Magic Post Thumbnail: from n/…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43921
|
2024-09-4 23:12 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313376
|
5.4 |
MEDIUM
Network
|
jegstudio
|
gutenverse
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jegstudio Gutenverse allows Stored XSS.This issue affects Gutenverse: from n/a through 1.9…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43920
|
2024-09-4 23:06 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313377
|
9.8 |
CRITICAL
Network
|
propovoice
|
propovoice
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Propovoice Propovoice Pro allows SQL Injection.This issue affects Propovoice Pro: from n/a throug…
|
CWE-89
SQL Injection
|
CVE-2024-43941
|
2024-09-4 22:40 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313378
|
6.5 |
MEDIUM
Network
|
serilog-contrib
|
serilog-enrichers-clientinfo
|
Serilog before v2.1.0 was discovered to contain a Client IP Spoofing vulnerability, which allows attackers to falsify their IP addresses by specifying an arbitrary IP as a value of X-Forwarded-For or…
|
NVD-CWE-noinfo
|
CVE-2024-44930
|
2024-09-4 21:59 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313379
|
8.8 |
HIGH
Network
|
easytest
|
easytest_online_test_platform
|
SQL Injection in mock exam function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the qlevel parameter.
|
CWE-89
SQL Injection
|
CVE-2024-43776
|
2024-09-4 21:27 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313380
|
8.8 |
HIGH
Network
|
easytest
|
easytest_online_test_platform
|
SQL Injection in search course titles function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the search parameter.
|
CWE-89
SQL Injection
|
CVE-2024-43775
|
2024-09-4 21:27 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|