|
251031
|
- |
|
-
|
-
|
A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name parameter. NOTE: this is disputed by the Supplier because it ca…
|
-
|
CVE-2024-46292
|
2024-10-21 09:15 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251032
|
8.8 |
HIGH
Network
|
ninjaforms
|
ninja_forms
|
Cross-Site Request Forgery (CSRF) vulnerability in Saturday Drive Ninja Forms allows Cross Site Request Forgery.This issue affects Ninja Forms: from n/a through 3.8.6.
|
CWE-352
Origin Validation Error
|
CVE-2024-39628
|
2024-10-20 21:15 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251033
|
4.3 |
MEDIUM
Network
|
discourse
|
discourse
|
Discourse is an open source platform for community discussion. A user can create a post with many replies, and then attempt to fetch them all at once. This can potentially reduce the availability of …
|
NVD-CWE-noinfo
|
CVE-2024-43789
|
2024-10-19 10:13 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251034
|
8.2 |
HIGH
Network
|
discourse
|
discourse
|
Discourse is an open source platform for community discussion. A maliciously crafted email address could allow an attacker to bypass domain-based restrictions and gain access to private sites, catego…
|
NVD-CWE-noinfo
|
CVE-2024-45051
|
2024-10-19 10:11 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251035
|
4.3 |
MEDIUM
Network
|
discourse
|
discourse
|
Discourse is an open source platform for community discussion. Users can see topics with a hidden tag if they know the label/name of that tag. This issue has been patched in the latest stable, beta a…
|
NVD-CWE-noinfo
|
CVE-2024-45297
|
2024-10-19 10:06 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251036
|
6.1 |
MEDIUM
Network
|
discourse
|
discourse
|
Discourse is an open source platform for community discussion. An attacker can execute arbitrary JavaScript on users' browsers by sending a maliciously crafted chat message and replying to it. This i…
|
CWE-79
Cross-site Scripting
|
CVE-2024-47772
|
2024-10-19 09:58 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251037
|
5.4 |
MEDIUM
Network
|
newtype
|
webeip
|
NewType WebEIP v3.0 does not properly validate user input, allowing a remote attacker with regular privileges to insert JavaScript into specific parameters, resulting in a Reflected Cross-site Script…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9969
|
2024-10-19 09:51 |
2024-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251038
|
4.9 |
MEDIUM
Network
|
usualtool
|
usualtoolcms
|
A vulnerability, which was classified as critical, was found in HuangDou UTCMS V9. This affects an unknown part of the file app/modules/ut-template/admin/template_creat.php. The manipulation of the a…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-9917
|
2024-10-19 09:49 |
2024-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251039
|
7.2 |
HIGH
Network
|
usualtool
|
usualtoolcms
|
A vulnerability has been found in HuangDou UTCMS V9 and classified as critical. This vulnerability affects the function RunSql of the file app/modules/ut-data/admin/sql.php. The manipulation of the a…
|
CWE-89
SQL Injection
|
CVE-2024-9918
|
2024-10-19 09:47 |
2024-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251040
|
7.5 |
HIGH
Network
|
dueclic
|
wp_2fa_with_telegram
|
The WP 2FA with Telegram plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and including, 3.0. This is due to the two-factor code being stored in a cookie, whi…
|
CWE-565
Reliance on Cookies without Validation and Integrity Checking
|
CVE-2024-9820
|
2024-10-19 09:44 |
2024-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|