|
250101
|
8.8 |
HIGH
Network
|
zohocorp
|
manageengine_adaudit_plus
|
Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in Technician reports option.
|
CWE-89
SQL Injection
|
CVE-2024-36485
|
2024-11-7 20:15 |
2024-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250102
|
- |
|
-
|
-
|
In OpenStack Ironic before 26.0.1 and ironic-python-agent before 9.13.1, there is a vulnerability in image processing, in which a crafted image could be used by an authenticated user to exploit undes…
|
-
|
CVE-2024-44082
|
2024-11-7 17:35 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250103
|
5.5 |
MEDIUM
Local
|
huawei
|
harmonyos
|
Vulnerability of input parameters not being verified in the HDC module
Impact: Successful exploitation of this vulnerability may affect availability.
|
NVD-CWE-noinfo
|
CVE-2024-51519
|
2024-11-7 08:15 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250104
|
7.5 |
HIGH
Network
|
huawei
|
harmonyos
|
Vulnerability of message types not being verified in the advanced messaging modul
Impact: Successful exploitation of this vulnerability may affect availability.
|
NVD-CWE-noinfo
|
CVE-2024-51518
|
2024-11-7 08:15 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250105
|
5.5 |
MEDIUM
Local
|
huawei
|
harmonyos
|
Vulnerability of improper memory access in the phone service module
Impact: Successful exploitation of this vulnerability may affect availability.
|
CWE-129
Improper Validation of Array Index
|
CVE-2024-51517
|
2024-11-7 08:15 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250106
|
8.8 |
HIGH
Network
|
darkmysite
|
darkmysite
|
Cross-Site Request Forgery (CSRF) vulnerability in DarkMySite DarkMySite – Advanced Dark Mode Plugin for WordPress darkmysite allows Cross Site Request Forgery.This issue affects DarkMySite – Advance…
|
CWE-352
Origin Validation Error
|
CVE-2024-50466
|
2024-11-7 08:13 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250107
|
9.8 |
CRITICAL
Network
|
hmplugin
|
aidwp
|
Missing Authorization vulnerability in HM Plugin WordPress Stripe Donation and Payment Plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Stri…
|
CWE-862
Missing Authorization
|
CVE-2024-50459
|
2024-11-7 08:11 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250108
|
5.3 |
MEDIUM
Network
|
openjsf
|
express
|
A vulnerability has been identified in the Express response.links function, allowing for arbitrary resource injection in the Link header when unsanitized data is used.
The issue arises from improper…
|
NVD-CWE-noinfo
|
CVE-2024-10491
|
2024-11-7 08:08 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250109
|
5.4 |
MEDIUM
Network
|
joshlobe
|
ultimate_tinymce
|
The Ultimate TinyMCE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'field' shortcode in all versions up to, and including, 5.7 due to insufficient input sanitization and o…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8627
|
2024-11-7 08:06 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250110
|
5.5 |
MEDIUM
Network
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sens…
|
CWE-611
XXE
|
CVE-2024-45086
|
2024-11-7 08:04 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|