|
305651
|
- |
|
-
|
-
|
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to check that the origin of the message in an integration action matches with the original post metadata which allows an au…
|
-
|
CVE-2024-50052
|
2024-10-29 17:15 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305652
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.4 via the render function in elements/tabs/tabs.php. …
|
CWE-200
Information Exposure
|
CVE-2024-10312
|
2024-10-29 17:15 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305653
|
- |
|
-
|
-
|
Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled which allows a user to get private channel names by using cmd+K/ctrl+K.
|
-
|
CVE-2024-10241
|
2024-10-29 17:15 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305654
|
8.8 |
HIGH
Network
|
-
|
-
|
The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to unauthorized user profile modification due to missing authorization checks on the /wp-json/…
|
CWE-862
Missing Authorization
|
CVE-2024-10008
|
2024-10-29 15:15 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305655
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the question's content parameter in all versions up to, and…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10000
|
2024-10-29 15:15 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305656
|
- |
|
-
|
-
|
There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authenticated attacker could use the vulnerability to exe…
|
-
|
CVE-2024-22065
|
2024-10-29 11:15 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305657
|
- |
|
-
|
-
|
A vulnerability, which was classified as problematic, was found in LinZhaoguan pb-cms up to 2.0.1. Affected is an unknown function of the file /admin#themes of the component Theme Management Module. …
|
CWE-79
Cross-site Scripting
|
CVE-2024-10479
|
2024-10-29 11:15 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305658
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
-
|
CVE-2024-43885
|
2024-10-29 11:15 |
2024-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305659
|
9.8 |
CRITICAL
Network
|
-
|
-
|
IBM Flexible Service Processor (FSP) FW860.00 through FW860.B3, FW950.00 through FW950.C0, FW1030.00 through FW1030.61, FW1050.00 through FW1050.21, and FW1060.00 through FW1060.10 has static credent…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2024-45656
|
2024-10-29 10:15 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305660
|
- |
|
-
|
-
|
A vulnerability, which was classified as problematic, has been found in LinZhaoguan pb-cms up to 2.0.1. This issue affects some unknown processing of the file /admin#article/edit?id=2 of the componen…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10478
|
2024-10-29 10:15 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|