|
251681
|
8.8 |
HIGH
Network
|
mediawiki
|
cargo
|
Cross-Site Request Forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows Cross Site Request Forgery.This issue affects Mediawiki - Cargo: from 3.6.X before 3.6.1.
|
CWE-352
Origin Validation Error
|
CVE-2024-47846
|
2024-10-17 01:42 |
2024-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251682
|
- |
|
-
|
-
|
On Microchip RN4870 devices, when more than one consecutive PairReqNoInputNoOutput request is
received, the device becomes incapable of completing the pairing
process. A third party can inject a se…
|
-
|
CVE-2024-29155
|
2024-10-17 01:38 |
2024-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251683
|
- |
|
-
|
-
|
Docker Desktop before v4.34.3 allows RCE via unsanitized GitHub source link in Build view.
|
-
|
CVE-2024-9348
|
2024-10-17 01:38 |
2024-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251684
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in nayon46 Unlimited Addon For Elementor allows Stored XSS.This issue affects Unlimited Addon…
|
CWE-79
Cross-site Scripting
|
CVE-2024-49267
|
2024-10-17 01:38 |
2024-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251685
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Thimo Grauerholz WP-Spreadplugin allows Stored XSS.This issue affects WP-Spreadplugin: fro…
|
CWE-79
Cross-site Scripting
|
CVE-2024-49266
|
2024-10-17 01:38 |
2024-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251686
|
- |
|
-
|
-
|
A Reflected Cross Site Scripting (XSS) vulnerability was found in /trms/listed- teachers.php in PHPGurukul Teachers Record Management System v2.1, which allows remote attackers to execute arbitrary c…
|
-
|
CVE-2024-48744
|
2024-10-17 01:38 |
2024-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251687
|
- |
|
-
|
-
|
A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Configuration utility that allows an attacker with the Administrator role to run JavaScript in the contex…
|
-
|
CVE-2024-47139
|
2024-10-17 01:38 |
2024-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251688
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.1.14. This is due to insufficient verification on the user being retur…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2024-9893
|
2024-10-17 01:38 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251689
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in HashThemes Smart Blocks allows Stored XSS.This issue affects Smart Blocks: from n/a throug…
|
CWE-79
Cross-site Scripting
|
CVE-2024-49270
|
2024-10-17 01:38 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251690
|
- |
|
-
|
-
|
Unrestricted Upload of File with Dangerous Type vulnerability in Limb WordPress Gallery Plugin – Limb Image Gallery allows Code Injection.This issue affects WordPress Gallery Plugin – Limb Image Gall…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-49260
|
2024-10-17 01:38 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|