|
249521
|
- |
|
-
|
-
|
An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is sent between client and server with encryption. However, the key is derived from the string "(c)2007 UCI Software Gm…
|
-
|
CVE-2024-45165
|
2024-11-1 04:35 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249522
|
5.4 |
MEDIUM
Network
|
cisco
|
secure_firewall_management_center
|
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack …
|
CWE-79
Cross-site Scripting
|
CVE-2024-20298
|
2024-11-1 04:25 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249523
|
6.1 |
MEDIUM
Network
|
cisco
|
firepower_management_center
|
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attac…
|
CWE-79
Cross-site Scripting
|
CVE-2024-20415
|
2024-11-1 04:17 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249524
|
6.1 |
MEDIUM
Network
|
cisco
|
secure_firewall_management_center
|
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attac…
|
CWE-79
Cross-site Scripting
|
CVE-2024-20273
|
2024-11-1 04:09 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249525
|
5.4 |
MEDIUM
Network
|
cisco
|
secure_firewall_management_center
|
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack …
|
CWE-79
Cross-site Scripting
|
CVE-2024-20264
|
2024-11-1 04:04 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249526
|
6.1 |
MEDIUM
Network
|
abdullahirfan
|
whitelist
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Abdullah Irfan Whitelist allows Reflected XSS.This issue affects Whitelist: from n/a throu…
|
CWE-79
Cross-site Scripting
|
CVE-2024-49643
|
2024-11-1 03:48 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249527
|
6.5 |
MEDIUM
Network
|
lunary
|
lunary
|
lunary-ai/lunary v1.2.26 contains an email injection vulnerability in the Send email verification API (/v1/users/send-verification) and Sign up API (/auth/signup). An unauthenticated attacker can inj…
|
CWE-74
Injection
|
CVE-2024-7472
|
2024-11-1 03:46 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249528
|
9.8 |
CRITICAL
Network
|
langchain
|
langchain
|
A vulnerability in the GraphCypherQAChain class of langchain-ai/langchainjs versions 0.2.5 and all versions with this class allows for prompt injection, leading to SQL injection. This vulnerability p…
|
CWE-89
SQL Injection
|
CVE-2024-7042
|
2024-11-1 03:36 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249529
|
9.1 |
CRITICAL
Network
|
gaizhenbiao
|
chuanhuchatgpt
|
A file overwrite vulnerability exists in gaizhenbiao/chuanhuchatgpt versions <= 20240410. This vulnerability allows an attacker to gain unauthorized access to overwrite critical configuration files w…
|
CWE-610
Externally Controlled Reference to a Resource in Another Sphere
|
CVE-2024-5823
|
2024-11-1 03:05 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249530
|
6.1 |
MEDIUM
Network
|
soft-master
|
affiliate_platform
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ilias Gomatos Affiliate Platform allows Reflected XSS.This issue affects Affiliate Platfor…
|
CWE-79
Cross-site Scripting
|
CVE-2024-49645
|
2024-11-1 02:59 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|