|
256721
|
4.3 |
MEDIUM
Network
|
majeedraza
|
carousel_slider
|
WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Carousel image selection feature. While logged in to the WordPress site with Carouse…
|
CWE-352
Origin Validation Error
|
CVE-2024-45269
|
2024-09-4 20:49 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256722
|
4.7 |
MEDIUM
Network
|
code-projects
|
pharmacy_management_system
|
A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /index.php?id=userProfileEdit of the compone…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8366
|
2024-09-4 20:26 |
2024-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256723
|
- |
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
-
|
CVE-2024-7821
|
2024-09-4 19:15 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256724
|
- |
|
-
|
-
|
YugabyteDB v2.21.1.0 was discovered to contain a buffer overflow via the "insert into" parameter.
|
-
|
CVE-2024-41435
|
2024-09-4 06:35 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256725
|
7.8 |
HIGH
Local
|
automationanywhere
|
automation_360
|
A CSV injection vulnerability in Automation Anywhere Automation 360 version 21094 allows attackers to execute arbitrary code via a crafted payload. NOTE: Automation Anywhere disputes this report, arg…
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2024-41226
|
2024-09-4 06:15 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256726
|
9.8 |
CRITICAL
Network
|
project_expense_monitoring_system_project
|
project_expense_monitoring_system
|
A vulnerability classified as critical was found in itsourcecode Project Expense Monitoring System 1.0. This vulnerability affects unknown code of the file printtransfer.php. The manipulation of the …
|
CWE-89
SQL Injection
|
CVE-2024-7937
|
2024-09-4 05:43 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256727
|
9.8 |
CRITICAL
Network
|
project_expense_monitoring_system_project
|
project_expense_monitoring_system
|
A vulnerability classified as critical has been found in itsourcecode Project Expense Monitoring System 1.0. This affects an unknown part of the file transferred_report.php. The manipulation of the a…
|
CWE-89
SQL Injection
|
CVE-2024-7936
|
2024-09-4 05:43 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256728
|
5.4 |
MEDIUM
Network
|
rems
|
leads_manager_tool
|
A vulnerability has been found in SourceCodester Leads Manager Tool 1.0 and classified as problematic. This vulnerability affects unknown code of the file update-leads.php. The manipulation of the ar…
|
CWE-79
Cross-site Scripting
|
CVE-2024-7942
|
2024-09-4 05:39 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256729
|
- |
|
-
|
-
|
ClickHouse v24.3.3.102 was discovered to contain a buffer overflow via the component DB::evaluateConstantExpressionImpl.
|
-
|
CVE-2024-41436
|
2024-09-4 05:35 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256730
|
- |
|
-
|
-
|
A CSV injection vulnerability in Lime Survey v6.5.12 allows attackers to execute arbitrary code via uploading a crafted CSV file.
|
-
|
CVE-2024-42901
|
2024-09-4 05:35 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|