|
250201
|
9.1 |
CRITICAL
Network
|
openrefine
|
butterfly
|
The OpenRefine fork of the MIT Simile Butterfly server is a modular web application framework. The Butterfly framework uses the `java.net.URL` class to refer to (what are expected to be) local resour…
|
CWE-22
Path Traversal
|
CVE-2024-47883
|
2024-10-30 00:38 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250202
|
- |
|
-
|
-
|
HCL Sametime is impacted by insecure services in-use on the UIM client by default. An unused legacy REST service was enabled by default using the HTTP protocol. An attacker could potentially use this…
|
-
|
CVE-2024-30124
|
2024-10-30 00:35 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250203
|
- |
|
-
|
-
|
An issue was discovered in Atos Eviden iCare 2.7.1 through 2.7.11. The application exposes a web interface locally. In the worst-case scenario, if the application is remotely accessible, it allows an…
|
-
|
CVE-2024-42017
|
2024-10-30 00:35 |
2024-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250204
|
- |
|
sgi
|
irix
|
root privileges via buffer overflow in ordist command on SGI IRIX systems.
|
NVD-CWE-Other
|
CVE-1999-0029
|
2024-10-30 00:35 |
1997-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250205
|
5.4 |
MEDIUM
Network
|
hikashop
|
hikashop
|
A stored cross-site scripting (XSS) vulnerability in HikaShop Joomla Component < 5.1.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious p…
|
CWE-79
Cross-site Scripting
|
CVE-2024-40746
|
2024-10-30 00:34 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250206
|
5.4 |
MEDIUM
Network
|
jesweb
|
anchor_episodes_index
|
The Anchor Episodes Index (Spotify for Podcasters) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's anchor_episodes shortcode in all versions up to, and including, 2…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10189
|
2024-10-30 00:27 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250207
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.6. An app may be able to cause a coprocessor crash.
|
CWE-787
Out-of-bounds Write
|
CVE-2024-40810
|
2024-10-30 00:21 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250208
|
4.3 |
MEDIUM
Network
|
colorlib
|
simple_custom_post_order
|
Missing Authorization vulnerability in Colorlib Simple Custom Post Order allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Custom Post Order: from n/a …
|
CWE-862
Missing Authorization
|
CVE-2024-49321
|
2024-10-30 00:20 |
2024-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250209
|
5.4 |
MEDIUM
Network
|
rextheme
|
wp_vr
|
Missing Authorization vulnerability in Rextheme WP VR allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP VR: from n/a through 8.5.4.
|
CWE-862
Missing Authorization
|
CVE-2024-49293
|
2024-10-30 00:07 |
2024-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250210
|
6.1 |
MEDIUM
Network
|
edit_woocommerce_templates_project
|
edit_woocommerce_templates
|
The Edit WooCommerce Templates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in all versions up to, and including, 1.1.2 due to insufficient input sani…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10049
|
2024-10-29 23:49 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|