|
256731
|
8.8 |
HIGH
Network
|
adonesevangelista
|
laravel_property_management_system
|
A vulnerability was found in itsourcecode Laravel Property Management System 1.0 and classified as critical. This issue affects the function upload of the file PropertiesController.php. The manipulat…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-7943
|
2024-09-4 05:35 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256732
|
5.4 |
MEDIUM
Network
|
posimyth
|
the_plus_addons_for_elementor
|
The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the video_date attribute wi…
|
CWE-79
Cross-site Scripting
|
CVE-2024-5763
|
2024-09-4 05:31 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256733
|
5.4 |
MEDIUM
Network
|
posimyth
|
the_plus_addons_for_elementor
|
The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘res_width_value’ param…
|
CWE-79
Cross-site Scripting
|
CVE-2024-6575
|
2024-09-4 05:30 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256734
|
5.4 |
MEDIUM
Network
|
sayandatta
|
wp_last_modified_info
|
The WP Last Modified Info plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘template’ attribute of the lmt-post-modified-info shortcode in all versions up to, and including, …
|
CWE-79
Cross-site Scripting
|
CVE-2024-6864
|
2024-09-4 05:22 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256735
|
6.1 |
MEDIUM
Network
|
priority-software
|
priority
|
Priority - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
|
CWE-79
Cross-site Scripting
|
CVE-2024-41697
|
2024-09-4 05:19 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256736
|
7.5 |
HIGH
Network
|
priority-software
|
priority
|
Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
|
CWE-200
Information Exposure
|
CVE-2024-41698
|
2024-09-4 05:18 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256737
|
7.5 |
HIGH
Network
|
priority-software
|
priority
|
Priority – CWE-552: Files or Directories Accessible to External Parties
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2024-41699
|
2024-09-4 05:17 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256738
|
7.5 |
HIGH
Network
|
mecodia
|
feripro
|
An Incorrect Access Control vulnerability in "/admin/programm/<program_id>/export/statistics" in Feripro <= v2.2.3 allows remote attackers to export an XLSX file with information about registrations …
|
NVD-CWE-Other
|
CVE-2024-41518
|
2024-09-4 05:15 |
2024-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256739
|
- |
|
-
|
-
|
An issue in the js_localize.php function of LimeSurvey v6.6.2 and before allows attackers to execute arbitrary code via injecting a crafted payload into the lng parameter of the js_localize.php funct…
|
-
|
CVE-2024-42902
|
2024-09-4 04:40 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256740
|
- |
|
-
|
-
|
The Bare Metal Operator (BMO) implements a Kubernetes API for managing bare metal hosts in Metal3. The `BareMetalHost` (BMH) CRD allows the `userData`, `metaData`, and `networkData` for the provision…
|
-
|
CVE-2024-43803
|
2024-09-4 04:40 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|