|
310011
|
4.3 |
MEDIUM
Network
|
brevo
|
newsletter\ _smtp\ _email_marketing_and_subscribe
|
The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.87. …
|
CWE-352
Origin Validation Error
|
CVE-2024-8477
|
2024-10-15 22:30 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310012
|
7.5 |
HIGH
Network
|
checkmk
|
checkmk
|
Information leakage in mknotifyd in Checkmk before 2.3.0p18, 2.2.0p36, 2.1.0p49 and in 2.0.0p39 (EOL) allows attacker to get potentially sensitive data
|
CWE-200
Information Exposure
|
CVE-2024-6747
|
2024-10-15 22:22 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310013
|
6.1 |
MEDIUM
Network
|
limesurvey
|
limesurvey
|
Cross Site Scripting vulnerability in LimeSurvey before 6.5.12+240611 allows a remote attacker to execute arbitrary code via a crafted script to the title and comment fields.
|
CWE-79
Cross-site Scripting
|
CVE-2024-28709
|
2024-10-15 22:19 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310014
|
6.1 |
MEDIUM
Network
|
limesurvey
|
limesurvey
|
Cross Site Scripting vulnerability in LimeSurvey before 6.5.0+240319 allows a remote attacker to execute arbitrary code via a lack of input validation and output encoding in the Alert Widget's messag…
|
CWE-79
Cross-site Scripting
|
CVE-2024-28710
|
2024-10-15 22:18 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310015
|
- |
|
-
|
-
|
An issue in sbondCo Watcharr v.1.43.0 allows a remote attacker to execute arbitrary code and escalate privileges via the Change Password function.
|
-
|
CVE-2024-48827
|
2024-10-15 21:58 |
2024-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310016
|
- |
|
-
|
-
|
SQL injection vulnerability in employee-management-system-php-and-mysql-free-download.html taskmatic 1.0 allows a remote attacker to execute arbitrary code via the admin_id parameter of the /update-e…
|
-
|
CVE-2024-48813
|
2024-10-15 21:58 |
2024-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310017
|
6.5 |
MEDIUM
Network
|
-
|
-
|
An Allocation of Resources Without Limits or Throttling vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved allows an authenticated, network-based attacker t…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2024-47509
|
2024-10-15 21:58 |
2024-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310018
|
- |
|
-
|
-
|
An Authorization Bypass Through User-Controlled Key vulnerability allows a locally authenticated attacker with shell access to gain full control of the device when Dual Routing Engines (REs) are in u…
|
-
|
CVE-2024-47495
|
2024-10-15 21:58 |
2024-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310019
|
- |
|
-
|
-
|
An arbitrary file upload vulnerability in the ProductAction.entphone interface of Zhejiang University Entersoft Customer Resource Management System v2002 to v2024 allows attackers to execute arbitrar…
|
-
|
CVE-2024-46088
|
2024-10-15 21:58 |
2024-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310020
|
- |
|
-
|
-
|
A Command Injection vulnerability in Juniper Networks Junos Space allows an unauthenticated, network-based attacker sending a specially crafted request to execute arbitrary shell commands on the Juno…
|
CWE-77
Command Injection
|
CVE-2024-39563
|
2024-10-15 21:58 |
2024-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|