|
250501
|
4.8 |
MEDIUM
Network
|
mitel
|
micollab
|
A vulnerability in the web conferencing component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attacker with administrative privileges to conduct a Stored Cross-Site Scripting (XS…
|
CWE-79
Cross-site Scripting
|
CVE-2024-30159
|
2024-10-26 01:30 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250502
|
7.2 |
HIGH
Network
|
mitel
|
micollab
|
A vulnerability in the web conferencing component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attacker with administrative privileges to conduct a SQL Injection attack due to ins…
|
CWE-89
SQL Injection
|
CVE-2024-30158
|
2024-10-26 01:30 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250503
|
7.2 |
HIGH
Network
|
wpovernight
|
woocommerce_order_proposal
|
The WooCommerce Order Proposal plugin for WordPress is vulnerable to privilege escalation via order proposal in all versions up to and including 2.0.5. This is due to the improper implementation of a…
|
CWE-287
Improper Authentication
|
CVE-2024-9927
|
2024-10-26 01:29 |
2024-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250504
|
5.4 |
MEDIUM
Network
|
rebelcode
|
rss_aggregator
|
The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the wprss_ajax…
|
CWE-862
Missing Authorization
|
CVE-2024-9583
|
2024-10-26 01:28 |
2024-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250505
|
3.1 |
LOW
Network
|
umbraco
|
umbraco_cms
|
Umbraco, a free and open source .NET content management system, has an insufficient session expiration issue in versions on the 13.x branch prior to 13.5.2, 10.x prior to 10.8.7, and 8.x prior to 8.1…
|
CWE-613
Insufficient Session Expiration
|
CVE-2024-48926
|
2024-10-26 01:19 |
2024-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250506
|
4.6 |
MEDIUM
Network
|
umbraco
|
umbraco_cms
|
Umbraco, a free and open source .NET content management system, has a remote code execution issue in versions on the 13.x branch prior to 13.5.2, 10.x prior to 10.8.7, and 8.x prior to 8.18.15. There…
|
CWE-79
Cross-site Scripting
|
CVE-2024-48927
|
2024-10-26 01:15 |
2024-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250507
|
- |
|
-
|
-
|
Cross Site Scripting vulnerability in JavaScript Library jquery-ui v.1.13.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted payload to the window.add…
|
-
|
CVE-2024-30875
|
2024-10-26 01:15 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250508
|
4.2 |
MEDIUM
Network
|
umbraco
|
umbraco_cms
|
Umbraco is a free and open source .NET content management system. In versions on the 13.x branch prior to 13.5.2 and versions on the 10.x branch prior to 10.8.7, during an explicit sign-out, the serv…
|
CWE-384
Session Fixation
|
CVE-2024-48929
|
2024-10-26 01:12 |
2024-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250509
|
9.8 |
CRITICAL
Network
|
ibm
|
concert
|
IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.
|
CWE-295
Improper Certificate Validation
|
CVE-2024-43177
|
2024-10-26 01:05 |
2024-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250510
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: fix use-after-free during gpu recovery
[Why]
[ 754.862560] refcount_t: underflow; use-after-free.
[ 754.862…
|
CWE-416
Use After Free
|
CVE-2022-48990
|
2024-10-26 01:03 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|