|
311901
|
8.8 |
HIGH
Network
|
mayurik
|
best_house_rental_management_system
|
A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. Affected is the function delete_user/save_user of the file /admin_class.php. The manip…
|
CWE-89
SQL Injection
|
CVE-2024-8709
|
2024-09-14 01:27 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311902
|
6.1 |
MEDIUM
Network
|
payara
|
payara
|
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server (REST Management Interface modules) allows Session Hijacking.This issue affects Payara Server: from …
|
CWE-601
Open Redirect
|
CVE-2024-7312
|
2024-09-14 01:27 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311903
|
8.8 |
HIGH
Network
|
code-projects
|
inventory_management
|
A vulnerability classified as critical was found in code-projects Inventory Management 1.0. Affected by this vulnerability is an unknown functionality of the file /model/viewProduct.php of the compon…
|
CWE-89
SQL Injection
|
CVE-2024-8710
|
2024-09-14 01:25 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311904
|
7.5 |
HIGH
Network
|
oretnom23
|
food_ordering_management_system
|
A vulnerability, which was classified as problematic, has been found in SourceCodester Food Ordering Management System 1.0. Affected by this issue is some unknown functionality of the file /includes/…
|
NVD-CWE-Other
|
CVE-2024-8711
|
2024-09-14 01:18 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311905
|
6.1 |
MEDIUM
Network
|
scriptonite
|
music_request_manager
|
The Music Request Manager WordPress plugin through 1.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin ad…
|
CWE-352
Origin Validation Error
|
CVE-2024-6017
|
2024-09-14 01:17 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311906
|
6.1 |
MEDIUM
Network
|
scriptonite
|
music_request_manager
|
The Music Request Manager WordPress plugin through 1.3 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Script…
|
CWE-79
Cross-site Scripting
|
CVE-2024-6018
|
2024-09-14 01:15 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311907
|
6.1 |
MEDIUM
Network
|
scriptonite
|
music_request_manager
|
The Music Request Manager WordPress plugin through 1.3 does not sanitise and escape incoming music requests, which could allow unauthenticated users to perform Cross-Site Scripting attacks against ad…
|
CWE-79
Cross-site Scripting
|
CVE-2024-6019
|
2024-09-14 01:13 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311908
|
4.8 |
MEDIUM
Network
|
pega
|
infinity
|
Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with App name.
|
CWE-79
Cross-site Scripting
|
CVE-2024-6700
|
2024-09-14 01:09 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311909
|
4.8 |
MEDIUM
Network
|
pega
|
infinity
|
Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with case type.
|
CWE-79
Cross-site Scripting
|
CVE-2024-6701
|
2024-09-14 01:08 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311910
|
4.8 |
MEDIUM
Network
|
pega
|
infinity
|
Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an HTML Injection issue with Stage.
|
CWE-79
Cross-site Scripting
|
CVE-2024-6702
|
2024-09-14 01:07 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|