|
250981
|
8.8 |
HIGH
Network
|
northernbeacheswebsites
|
ideapush
|
Cross-Site Request Forgery (CSRF) vulnerability in Martin Gibson IdeaPush allows Cross Site Request Forgery.This issue affects IdeaPush: from n/a through 8.69.
|
CWE-352
Origin Validation Error
|
CVE-2024-49275
|
2024-10-23 03:36 |
2024-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250982
|
8.8 |
HIGH
Network
|
wp-buy
|
wp_content_copy_protection_\&_no_right_click
|
Cross-Site Request Forgery (CSRF) vulnerability in WP-buy WP Content Copy Protection & No Right Click allows Cross Site Request Forgery.This issue affects WP Content Copy Protection & No Right Click:…
|
CWE-352
Origin Validation Error
|
CVE-2024-49306
|
2024-10-23 03:35 |
2024-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250983
|
8.8 |
HIGH
Network
|
boxystudio
|
cooked
|
Cross-Site Request Forgery (CSRF) vulnerability in Gora Tech LLC Cooked Pro allows Cross Site Request Forgery.This issue affects Cooked Pro: from n/a before 1.8.0.
|
CWE-352
Origin Validation Error
|
CVE-2024-49290
|
2024-10-23 03:35 |
2024-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250984
|
5.4 |
MEDIUM
Network
|
phpgurukul
|
hospital_management_system
|
PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) via the patname, pataddress, and medhis parameters in doctor/add-patient.php and doctor/edit-patient.php.
|
CWE-79
Cross-site Scripting
|
CVE-2024-46237
|
2024-10-23 03:35 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250985
|
8.8 |
HIGH
Network
|
noorsplugin
|
wordpress_image_seo
|
Cross-Site Request Forgery (CSRF) vulnerability in Noor Alam WordPress Image SEO allows Cross Site Request Forgery.This issue affects WordPress Image SEO: from n/a through 1.1.4.
|
CWE-352
Origin Validation Error
|
CVE-2024-49627
|
2024-10-23 03:33 |
2024-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250986
|
8.8 |
HIGH
Network
|
wpdiscover
|
photo_gallery_builder
|
Subscriber Broken Access Control in Photo Gallery Builder <= 3.0 versions.
|
CWE-862
Missing Authorization
|
CVE-2024-49325
|
2024-10-23 03:33 |
2024-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250987
|
8.8 |
HIGH
Network
|
whiletrue
|
most_and_least_read_posts_widget
|
Cross-Site Request Forgery (CSRF) vulnerability in WhileTrue Most And Least Read Posts Widget allows Cross Site Request Forgery.This issue affects Most And Least Read Posts Widget: from n/a through 2…
|
CWE-352
Origin Validation Error
|
CVE-2024-49628
|
2024-10-23 03:31 |
2024-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250988
|
6.0 |
MEDIUM
Local
|
cisco
|
ata_191_firmware ata_192_firmware
|
A vulnerability in the CLI of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an authenticated, local attacker with high privileges to execute arbitrary commands as the root u…
|
CWE-78
OS Command
|
CVE-2024-20461
|
2024-10-23 03:26 |
2024-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250989
|
5.4 |
MEDIUM
Network
|
code-projects
|
blood_bank_system
|
A vulnerability has been found in code-projects Blood Bank System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /viewrequest.php. The manipulation leads to cr…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10142
|
2024-10-23 03:11 |
2024-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250990
|
8.8 |
HIGH
Network
|
esafenet
|
cdg
|
A vulnerability was found in ESAFENET CDG 5 and classified as critical. Affected by this issue is the function connectLogout of the file /com/esafenet/servlet/ajax/MultiServerAjax.java. The manipulat…
|
CWE-89
SQL Injection
|
CVE-2024-10134
|
2024-10-23 03:10 |
2024-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|