|
251261
|
6.9 |
MEDIUM
Network
|
openrefine
|
openrefine
|
OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `export-rows` command can be used in such a way that it reflects part of the request verbatim, with a C…
|
CWE-79
Cross-site Scripting
|
CVE-2024-47880
|
2024-10-31 02:42 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251262
|
- |
|
-
|
-
|
File Upload vulnerability in Prison Management System v.1.0 allows a remote attacker to execute arbitrary code via the file upload component.
|
-
|
CVE-2024-48594
|
2024-10-31 02:35 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251263
|
- |
|
-
|
-
|
LyLme Spage <=1.6.0 is vulnerable to SQL Injection via /admin/group.php.
|
-
|
CVE-2024-48356
|
2024-10-31 02:35 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251264
|
- |
|
-
|
-
|
MRCMS 3.1.2 contains a SQL injection vulnerability via the RID parameter in /admin/article/delete.do.
|
-
|
CVE-2024-48177
|
2024-10-31 02:35 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251265
|
- |
|
-
|
-
|
SparkShop <=1.1.7 is vulnerable to server-side request forgery (SSRF). This vulnerability allows attacks to scan ports on the Intranet or local network where the server resides, attack applications r…
|
-
|
CVE-2024-48107
|
2024-10-31 02:35 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251266
|
- |
|
-
|
-
|
LyLme Spage 1.2.0 through 1.6.0 is vulnerable to SQL Injection via /admin/apply.php.
|
-
|
CVE-2024-48357
|
2024-10-31 02:35 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251267
|
- |
|
-
|
-
|
An issue was discovered in Samsung eMMC with KLMAG2GE4A and KLM8G1WEMB firmware. Code bypass through Electromagnetic Fault Injection allows an attacker to successfully authenticate and write to the R…
|
-
|
CVE-2024-31955
|
2024-10-31 02:35 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251268
|
5.3 |
MEDIUM
Network
|
djangoproject
|
django
|
An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The django.contrib.auth.forms.PasswordResetForm class, when used in a view implementing password reset flows, allows remote attackers to…
|
NVD-CWE-noinfo
|
CVE-2024-45231
|
2024-10-31 02:35 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251269
|
7.5 |
HIGH
Network
|
djangoproject
|
django
|
An issue was discovered in Django 5.1 before 5.1.1, 5.0 before 5.0.9, and 4.2 before 4.2.16. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via ve…
|
NVD-CWE-noinfo
|
CVE-2024-45230
|
2024-10-31 02:35 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251270
|
7.5 |
HIGH
Network
|
mozilla
|
firefox thunderbird firefox_esr
|
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js` origin. This could allow them to access cross-origin PDF content. This acces…
|
NVD-CWE-Other
|
CVE-2024-9393
|
2024-10-31 02:35 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|