|
251111
|
7.1 |
HIGH
Local
|
microsoft
|
windows_10_1809 windows_server_2019 windows_10_21h2 windows_10_22h2
|
Windows Kernel Elevation of Privilege Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-43502
|
2024-10-18 05:58 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251112
|
5.4 |
MEDIUM
Network
|
zaytech
|
smart_online_order_for_clover
|
The Smart Online Order for Clover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's moo_receipt_link shortcode in all versions up to, and including, 1.5.7 due to insu…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9895
|
2024-10-18 05:50 |
2024-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251113
|
6.1 |
MEDIUM
Network
|
woocommerce
|
woocommerce
|
The WooCommerce plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 9.0.2. This is due to the plugin not properly neutralizing HTML elements from submitted orde…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9944
|
2024-10-18 05:47 |
2024-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251114
|
6.1 |
MEDIUM
Network
|
quantizor
|
markdown-to-jsx
|
Versions of the package markdown-to-jsx before 7.4.0 are vulnerable to Cross-site Scripting (XSS) via the src property due to improper input sanitization. An attacker can execute arbitrary code by in…
|
CWE-79
Cross-site Scripting
|
CVE-2024-21535
|
2024-10-18 05:36 |
2024-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251115
|
8.8 |
HIGH
Network
|
newtype
|
flowmaster_bpm_plus
|
The specific query functionality in the FlowMaster BPM Plus from NewType does not properly restrict user input, allowing remote attackers with regular privileges to inject SQL commands to read, modif…
|
CWE-89
SQL Injection
|
CVE-2024-9971
|
2024-10-18 05:34 |
2024-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251116
|
8.8 |
HIGH
Network
|
newtype
|
flowmaster_bpm_plus
|
The FlowMaster BPM Plus system from NewType has a privilege escalation vulnerability. Remote attackers with regular privileges can elevate their privileges to administrator by tampering with a specif…
|
NVD-CWE-noinfo
|
CVE-2024-9970
|
2024-10-18 05:33 |
2024-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251117
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in Payments in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted …
|
NVD-CWE-noinfo
|
CVE-2024-9964
|
2024-10-18 05:30 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251118
|
7.5 |
HIGH
Network
|
microsoft
|
windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2022_23h2 windows_10_1809 windows_server_2022 windows_10_1607 windows_server_2019 windows_11_21h2
|
BranchCache Denial of Service Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-43506
|
2024-10-18 05:19 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251119
|
7.8 |
HIGH
Local
|
microsoft
|
sharepoint_server
|
Microsoft SharePoint Elevation of Privilege Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-43503
|
2024-10-18 05:19 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251120
|
7.8 |
HIGH
Local
|
solarwinds
|
solarwinds_platform
|
SolarWinds Platform is susceptible to an Uncontrolled Search Path Element Local Privilege Escalation vulnerability. This requires a low privilege account and local access to the affected node machine.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2024-45710
|
2024-10-18 05:18 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|