|
249301
|
9.8 |
CRITICAL
Network
|
filemanagerpro
|
file_manager
|
The File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the /inc/root.php file in versions up to, and including, 3.0. This makes it possible …
|
CWE-862
Missing Authorization
|
CVE-2018-25105
|
2024-10-31 03:23 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249302
|
6.1 |
MEDIUM
Network
|
cvat
|
computer_vision_annotation_tool
|
Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. If an attacker can trick a logged-in CVAT user into visiting a maliciously-constructed UR…
|
CWE-79 CWE-81
Cross-site Scripting Improper Neutralization of Script in an Error Message Web Page
|
CVE-2024-47064
|
2024-10-31 03:23 |
2024-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249303
|
9.8 |
CRITICAL
Network
|
codezips
|
pet_shop_management_system
|
A vulnerability was found in Codezips Pet Shop Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /deleteanimal.php. The manipulation of the …
|
CWE-89
SQL Injection
|
CVE-2024-10427
|
2024-10-31 03:21 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249304
|
7.5 |
HIGH
Network
|
vasyltech
|
advanced_access_manager
|
The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to, and including, 5.9.8.1 due to insufficient validation on the aam-media paramet…
|
CWE-22
Path Traversal
|
CVE-2019-25213
|
2024-10-31 03:20 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249305
|
5.4 |
MEDIUM
Network
|
cvat
|
computer_vision_annotation_tool
|
Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with a CVAT account may retrieve certain information about any project, task,…
|
CWE-863
Incorrect Authorization
|
CVE-2024-47172
|
2024-10-31 03:20 |
2024-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249306
|
9.8 |
CRITICAL
Network
|
kaswara_project
|
kaswara
|
The Kaswara Modern VC Addons plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.0.1 due to insufficient capability checking on various AJAX actions. This m…
|
CWE-862
Missing Authorization
|
CVE-2021-4448
|
2024-10-31 03:18 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249307
|
9.8 |
CRITICAL
Network
|
codezips
|
pet_shop_management_system
|
A vulnerability was found in Codezips Pet Shop Management System 1.0. It has been classified as critical. This affects an unknown part of the file /animalsadd.php. The manipulation of the argument id…
|
CWE-89
SQL Injection
|
CVE-2024-10426
|
2024-10-31 03:16 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249308
|
- |
|
-
|
-
|
ABB is aware of privately reported vulnerabilities in the product versions referenced in this CVE. An attacker could exploit these vulnerabilities by sending a specially crafted firmware or configura…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2024-8036
|
2024-10-31 03:15 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249309
|
7.1 |
HIGH
Local
|
apple
|
iphone_os ipados visionos tvos
|
A logic issue was addressed with improved file handling. This issue is fixed in iOS 18.1 and iPadOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, visionOS 2.1, tvOS 18.1. Restoring a maliciously crafted backup…
|
NVD-CWE-noinfo
|
CVE-2024-44252
|
2024-10-31 03:11 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249310
|
9.8 |
CRITICAL
Network
|
codezips
|
pet_shop_management_system
|
A vulnerability, which was classified as critical, was found in Codezips Pet Shop Management System 1.0. Affected is an unknown function of the file /deletebird.php. The manipulation of the argument …
|
CWE-89
SQL Injection
|
CVE-2024-10431
|
2024-10-31 03:10 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|