|
251801
|
6.5 |
MEDIUM
Network
|
shilpisoft
|
client_dashboard
|
This vulnerability exists in Shilpi Client Dashboard due to lack of authorization for modification and cancellation requests through certain API endpoints. An authenticated remote attacker could expl…
|
NVD-CWE-Other
|
CVE-2024-47653
|
2024-10-17 00:13 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251802
|
6.1 |
MEDIUM
Network
|
wp-centrics
|
fish_and_ships
|
The Fish and Ships – Most flexible shipping table rate. A WooCommerce shipping rate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without approp…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9237
|
2024-10-17 00:10 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251803
|
4.8 |
MEDIUM
Network
|
oretnom23
|
online_eyewear_shop
|
A vulnerability was found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. This issue affects some unknown processing of the file /admin/?page=system_info/contact_info of the …
|
CWE-79
Cross-site Scripting
|
CVE-2024-9952
|
2024-10-17 00:05 |
2024-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251804
|
9.8 |
CRITICAL
Network
|
magicbug
|
cloudlog
|
Cloudlog 2.6.15 allows Oqrs.php delete_oqrs_line id SQL injection.
|
CWE-89
SQL Injection
|
CVE-2024-48253
|
2024-10-16 23:27 |
2024-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251805
|
9.8 |
CRITICAL
Network
|
magicbug
|
cloudlog
|
Cloudlog 2.6.15 allows Oqrs.php get_station_info station_id SQL injection.
|
CWE-89
SQL Injection
|
CVE-2024-48255
|
2024-10-16 23:26 |
2024-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251806
|
6.1 |
MEDIUM
Network
|
nerdpress
|
smart_custom_404_error_page
|
The Smart Custom 404 Error Page plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_SERVER['REQUEST_URI'] in all versions up to, and including, 11.4.7 due to insufficient input…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9204
|
2024-10-16 23:26 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251807
|
9.8 |
CRITICAL
Network
|
wavelog
|
wavelog
|
Wavelog 1.8.5 allows Oqrs_model.php get_worked_modes station_id SQL injectioin.
|
CWE-89
SQL Injection
|
CVE-2024-48257
|
2024-10-16 23:24 |
2024-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251808
|
8.8 |
HIGH
Network
|
dlink
|
dir-619l_firmware
|
A vulnerability classified as critical has been found in D-Link DIR-619L B1 2.06. Affected is the function formResetStatistic of the file /goform/formResetStatistic. The manipulation of the argument …
|
CWE-120
Classic Buffer Overflow
|
CVE-2024-9784
|
2024-10-16 23:12 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251809
|
8.1 |
HIGH
Network
|
shilpisoft
|
client_dashboard
|
This vulnerability exists in Shilpi Client Dashboard due to implementation of inadequate authentication mechanism in the login module wherein access to any users account is granted with just their co…
|
NVD-CWE-Other
|
CVE-2024-47652
|
2024-10-16 23:12 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251810
|
5.7 |
MEDIUM
Network
|
enalean
|
tuleap
|
Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.40, Tuleap Enterprise Edition 15.13-3, and Tuleap Enterprise Edition 15…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2024-46988
|
2024-10-16 23:07 |
2024-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|