|
248911
|
5.4 |
MEDIUM
Network
|
brandevolutionco
|
themeshark_templates_\&_widgets_for_elementor
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemeShark ThemeShark Templates & Widgets for Elementor allows Stored XSS.This issue affec…
|
CWE-79
Cross-site Scripting
|
CVE-2024-51597
|
2024-11-15 05:27 |
2024-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248912
|
5.4 |
MEDIUM
Network
|
wpcirqle
|
bigmart_elements
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in wpcirqle Bigmart Elements allows DOM-Based XSS.This issue affects Bigmart Elements: from n…
|
CWE-79
Cross-site Scripting
|
CVE-2024-51589
|
2024-11-15 05:26 |
2024-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248913
|
5.4 |
MEDIUM
Network
|
themehat
|
super_addons_for_elementor
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themehat Super Addons for Elementor allows DOM-Based XSS.This issue affects Super Addons f…
|
CWE-79
Cross-site Scripting
|
CVE-2024-51588
|
2024-11-15 05:26 |
2024-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248914
|
5.4 |
MEDIUM
Network
|
softfirm
|
definitive_addons_for_elementor
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Softfirm Definitive Addons for Elementor allows Stored XSS.This issue affects Definitive A…
|
CWE-79
Cross-site Scripting
|
CVE-2024-51587
|
2024-11-15 05:26 |
2024-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248915
|
5.4 |
MEDIUM
Network
|
bu
|
bu_slideshow
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Boston University (IS&T) BU Slideshow allows Stored XSS.This issue affects BU Slideshow: f…
|
CWE-79
Cross-site Scripting
|
CVE-2024-52351
|
2024-11-15 05:24 |
2024-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248916
|
5.4 |
MEDIUM
Network
|
crm2go
|
crm2go
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CRM 2go allows DOM-Based XSS.This issue affects CRM 2go: from n/a through 1.0.
|
CWE-79
Cross-site Scripting
|
CVE-2024-52350
|
2024-11-15 05:22 |
2024-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248917
|
8.1 |
HIGH
Network
|
ampache
|
ampache
|
Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSRF tokens when activating or deactivating controlle…
|
CWE-352
Origin Validation Error
|
CVE-2024-51484
|
2024-11-15 05:14 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248918
|
5.4 |
MEDIUM
Network
|
ampache
|
ampache
|
Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing does not adequately validate CSRF tokens when users delete messages. This vulner…
|
CWE-352
Origin Validation Error
|
CVE-2024-51488
|
2024-11-15 05:12 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248919
|
8.1 |
HIGH
Network
|
ampache
|
ampache
|
Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSRF tokens when activating or deactivating plugins. …
|
CWE-352
Origin Validation Error
|
CVE-2024-51485
|
2024-11-15 05:06 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248920
|
4.3 |
MEDIUM
Network
|
futuriowp
|
futurio_extra
|
The Futurio Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.0.13 via the 'elementor-template' shortcode due to insufficient restrictions on wh…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-10695
|
2024-11-15 04:44 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|