|
308731
|
- |
|
-
|
-
|
localai <=2.20.1 is vulnerable to Cross Site Scripting (XSS). When calling the delete model API and passing inappropriate parameters, it can cause a one-time storage XSS, which will trigger the paylo…
|
-
|
CVE-2024-48057
|
2024-11-6 03:35 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308732
|
- |
|
-
|
-
|
Chamilo LMS Version 1.11.26 is vulnerable to Incorrect Access Control. A non-authenticated attacker can request the number of messages and the number of online users via "/main/inc/ajax/message.ajax.…
|
-
|
CVE-2024-30619
|
2024-11-6 03:35 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308733
|
- |
|
-
|
-
|
A Stored Cross-Site Scripting (XSS) Vulnerability in Chamilo LMS 1.11.26 allows a remote attacker to execute arbitrary JavaScript in a web browser by including a malicious payload in the 'content' pa…
|
-
|
CVE-2024-30618
|
2024-11-6 03:35 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308734
|
- |
|
-
|
-
|
Yealink Meeting Server before V26.0.0.67 is vulnerable to sensitive data exposure in the server response via sending HTTP request with enterprise ID.
|
-
|
CVE-2024-48352
|
2024-11-6 03:35 |
2024-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308735
|
- |
|
-
|
-
|
Altai Technologies Ltd Altai IX500 Indoor 22 802.11ac Wave 2 AP After login, there are file reads in the background, and attackers can obtain sensitive information such as user credentials, system co…
|
-
|
CVE-2024-51399
|
2024-11-6 03:35 |
2024-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308736
|
- |
|
-
|
-
|
Altai Technologies Ltd Altai X500 Indoor 22 802.11ac Wave 2 AP web Management Weak password leakage in the background may lead to unauthorized access, data theft, and network attacks, seriously threa…
|
-
|
CVE-2024-51398
|
2024-11-6 03:35 |
2024-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308737
|
9.8 |
CRITICAL
Network
|
codezips
|
free_exam_hall_seating_management_system
|
A vulnerability classified as critical has been found in Codezips Free Exam Hall Seating Management System 1.0. Affected is an unknown function of the file /teacher.php. The manipulation of the argum…
|
CWE-89
SQL Injection
|
CVE-2024-10737
|
2024-11-6 03:03 |
2024-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308738
|
9.8 |
CRITICAL
Network
|
codezips
|
free_exam_hall_seating_management_system
|
A vulnerability was found in Codezips Free Exam Hall Seating Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /student.php. The manipulatio…
|
CWE-89
SQL Injection
|
CVE-2024-10736
|
2024-11-6 03:03 |
2024-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308739
|
9.8 |
CRITICAL
Network
|
codezips
|
pet_shop_management_system
|
A vulnerability was found in Codezips Pet Shop Management System 1.0. It has been classified as critical. This affects an unknown part of the file /productsadd.php. The manipulation of the argument i…
|
CWE-89
SQL Injection
|
CVE-2024-10752
|
2024-11-6 02:59 |
2024-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308740
|
5.4 |
MEDIUM
Network
|
tezzeract
|
league_of_legends_shortcodes
|
The League of Legends Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 1.0.1 due to insufficient input sanitization and ou…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10342
|
2024-11-6 02:52 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|