|
249141
|
5.4 |
MEDIUM
Network
|
-
|
-
|
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Age Gate Widget '…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9868
|
2024-11-4 10:35 |
2024-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249142
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The ReCaptcha Integration for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8739
|
2024-11-4 10:35 |
2024-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249143
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress plugin for WordPress is vulnerable to SQL Injection via the 'service' parameter of the bookingpress_form shortcode in all …
|
CWE-89
SQL Injection
|
CVE-2024-10540
|
2024-11-4 10:35 |
2024-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249144
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Gallery Wi…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10310
|
2024-11-4 10:35 |
2024-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249145
|
- |
|
-
|
-
|
The issue was addressed with improved bounds checks. This issue is fixed in macOS Sonoma 14.7.1, macOS Ventura 13.7.1, visionOS 2.1, watchOS 11.1, tvOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 an…
|
-
|
CVE-2024-44234
|
2024-11-4 10:35 |
2024-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249146
|
- |
|
-
|
-
|
The issue was addressed with improved bounds checks. This issue is fixed in macOS Sonoma 14.7.1, macOS Ventura 13.7.1, visionOS 2.1, watchOS 11.1, tvOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 an…
|
-
|
CVE-2024-44233
|
2024-11-4 10:35 |
2024-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249147
|
- |
|
-
|
-
|
The issue was addressed with improved bounds checks. This issue is fixed in macOS Sonoma 14.7.1, macOS Ventura 13.7.1, visionOS 2.1, watchOS 11.1, tvOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 an…
|
-
|
CVE-2024-44232
|
2024-11-4 10:35 |
2024-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249148
|
6.5 |
MEDIUM
Network
|
lunary
|
lunary
|
An IDOR vulnerability exists in the 'Evaluations' function of the 'umgws datasets' section in lunary-ai/lunary versions 1.3.2. This vulnerability allows an authenticated user to update other users' p…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-7473
|
2024-11-4 02:15 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249149
|
7.1 |
HIGH
Network
|
lollms
|
lollms_web_ui
|
A vulnerability in parisneo/lollms-webui version 9.8 allows for a Denial of Service (DOS) attack when uploading an audio file. If an attacker appends a large number of characters to the end of a mult…
|
CWE-352
Origin Validation Error
|
CVE-2024-6959
|
2024-11-4 02:15 |
2024-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249150
|
2.7 |
LOW
Network
|
openwebui
|
open_webui
|
An information disclosure vulnerability exists in open-webui version 0.3.8. The vulnerability is related to the embedding model update feature under admin settings. When a user updates the model path…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2024-7038
|
2024-11-4 02:15 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|