|
250861
|
- |
|
-
|
-
|
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify was vulnerable to prototype pollution. This vulnerability is fixed in 2.4.2.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2024-48910
|
2024-11-1 21:57 |
2024-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250862
|
- |
|
-
|
-
|
DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the setup_cacertificate function.
|
-
|
CVE-2024-51259
|
2024-11-1 21:57 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250863
|
- |
|
-
|
-
|
DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the sign_cacertificate function.
|
-
|
CVE-2024-51254
|
2024-11-1 21:57 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250864
|
- |
|
-
|
-
|
langflow v1.0.12 was discovered to contain a remote code execution (RCE) vulnerability via the PythonCodeTool component.
|
-
|
CVE-2024-42835
|
2024-11-1 21:57 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250865
|
- |
|
-
|
-
|
A local user with administrative access rights can enter specialy crafted values for settings at the user interface (UI) of the TwinCAT Package Manager which then causes arbitrary OS commands to be e…
|
CWE-78
OS Command
|
CVE-2024-8934
|
2024-11-1 21:57 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250866
|
- |
|
-
|
-
|
Clickjacking vulnerability in Clibo Manager v1.1.9.12 in the '/public/login' directory, a login panel. This vulnerability occurs due to the absence of an X-Frame-Options server-side header. An attack…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2024-10454
|
2024-11-1 21:57 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250867
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Custom Twitter Feeds (Tweets Widget) allows Cross Site Request Forgery.This issue affects Custom Twitter Feeds (Tweets Widget): from n…
|
CWE-352
Origin Validation Error
|
CVE-2024-49685
|
2024-11-1 21:57 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250868
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in Lukas Huser EKC Tournament Manager allows Upload a Web Shell to a Web Server.This issue affects EKC Tournament Manager: from n/a through 2.2.1.
|
CWE-352
Origin Validation Error
|
CVE-2024-49674
|
2024-11-1 21:57 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250869
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher allows Code Injection.This issue affects Podlove Podcast Publisher: from n/a through 4.1.13.
|
CWE-352
Origin Validation Error
|
CVE-2024-43984
|
2024-11-1 21:57 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250870
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in WPMobile.App allows Stored XSS.This issue affects WPMobile.App: from n/a through 11.48.
|
CWE-352
Origin Validation Error
|
CVE-2024-43933
|
2024-11-1 21:57 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|