|
313851
|
6.1 |
MEDIUM
Network
|
3ds
|
3dexperience
|
A reflected Cross-site Scripting (XSS) vulnerability affecting 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in use…
|
CWE-79
Cross-site Scripting
|
CVE-2024-6379
|
2024-08-27 18:15 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313852
|
- |
|
-
|
-
|
The Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.4.1 …
|
-
|
CVE-2024-8046
|
2024-08-27 17:15 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313853
|
6.1 |
MEDIUM
Network
|
3ds
|
3dexperience
|
An URL redirection to untrusted site (open redirect) vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to redirect…
|
CWE-601
Open Redirect
|
CVE-2024-6377
|
2024-08-27 17:15 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313854
|
- |
|
-
|
-
|
Authentication Bypass vulnerability in Hitachi Ops Center Common Services.This issue affects Hitachi Ops Center Common Services: from 10.9.3-00 before 11.0.2-01.
|
-
|
CVE-2024-7125
|
2024-08-27 14:15 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313855
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Oxygen Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the oxy_save_css_from_admin AJAX action in all versions up to, and incl…
|
-
|
CVE-2024-6688
|
2024-08-27 14:15 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313856
|
- |
|
-
|
-
|
Rejected reason: Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that the issue does not pose a secu…
|
-
|
CVE-2024-7989
|
2024-08-27 06:15 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313857
|
- |
|
-
|
-
|
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accid…
|
-
|
CVE-2024-8188
|
2024-08-27 05:15 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313858
|
9.8 |
CRITICAL
Network
|
givewp
|
givewp
|
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.1 via deserialization of untrusted input fr…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-5932
|
2024-08-27 03:34 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313859
|
6.5 |
MEDIUM
Network
|
ibm
|
global_configuration_management
|
IBM Global Configuration Management 7.0.2 and 7.0.3 could allow an authenticated user to archive a global baseline due to improper access controls.
|
NVD-CWE-Other
|
CVE-2024-41773
|
2024-08-27 03:33 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313860
|
6.5 |
MEDIUM
Network
|
ghost
|
ghost
|
Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information. Th…
|
CWE-287
Improper Authentication
|
CVE-2024-43409
|
2024-08-27 03:31 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|