|
250961
|
5.4 |
MEDIUM
Network
|
madrasthemes
|
mas_elementor
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MadrasThemes MAS Elementor allows DOM-Based XSS.This issue affects MAS Elementor: from n/a…
|
CWE-79
Cross-site Scripting
|
CVE-2024-49233
|
2024-10-22 02:17 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250962
|
5.4 |
MEDIUM
Network
|
themeworm
|
plexx_elementor_extension
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in themeworm Plexx Elementor Extension allows Stored XSS.This issue affects Plexx Elementor E…
|
CWE-79
Cross-site Scripting
|
CVE-2024-49234
|
2024-10-22 02:16 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250963
|
5.4 |
MEDIUM
Network
|
hafizuddinahmed
|
crazy_call_to_action_box
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hafiz Uddin Ahmed Crazy Call To Action Box allows Stored XSS.This issue affects Crazy Call…
|
CWE-79
Cross-site Scripting
|
CVE-2024-49236
|
2024-10-22 02:12 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250964
|
- |
|
-
|
-
|
Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a remote authenticated attacker to achieve remote c…
|
-
|
CVE-2024-37404
|
2024-10-22 02:10 |
2024-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250965
|
- |
|
-
|
-
|
Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector.
|
-
|
CVE-2024-29821
|
2024-10-22 02:10 |
2024-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250966
|
- |
|
-
|
-
|
Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector.
|
-
|
CVE-2024-29213
|
2024-10-22 02:10 |
2024-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250967
|
- |
|
-
|
-
|
ACON is a widely-used library of tools for machine learning that focuses on adaptive correlation optimization. A potential vulnerability has been identified in the input validation process, which cou…
|
CWE-20
Improper Input Validation
|
CVE-2024-49361
|
2024-10-22 02:10 |
2024-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250968
|
- |
|
-
|
-
|
In J2eeFAST <=2.7, the backend function has unsafe filtering, which allows an attacker to trigger certain sensitive functions resulting in arbitrary code execution.
|
-
|
CVE-2024-45944
|
2024-10-22 02:10 |
2024-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250969
|
- |
|
-
|
-
|
Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.24, contains a Use of a Broken or Risky Cryptographic Algorithm vulnerability. A low privileged attacker with remote access could p…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2024-48016
|
2024-10-22 02:10 |
2024-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250970
|
- |
|
-
|
-
|
Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.24, contains an Improper Certificate Validation vulnerability. A low privileged attacker with remote access could potentially explo…
|
CWE-295
Improper Certificate Validation
|
CVE-2024-47241
|
2024-10-22 02:10 |
2024-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|