|
307681
|
- |
|
-
|
-
|
Cavok – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
|
CWE-89
SQL Injection
|
CVE-2024-45249
|
2024-10-8 02:47 |
2024-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307682
|
- |
|
-
|
-
|
Multi-DNC – CWE-35: Path Traversal: '.../...//'
|
CWE-35
Path Traversal: '.../...//'
|
CVE-2024-45248
|
2024-10-8 02:47 |
2024-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307683
|
- |
|
-
|
-
|
A vulnerability classified as problematic was found in Sovell Smart Canteen System up to 3.0.7303.30513. Affected by this vulnerability is the function Check_ET_CheckPwdz201 of the file suanfa.py of …
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-9554
|
2024-10-8 02:47 |
2024-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307684
|
- |
|
-
|
-
|
Sonarr – CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
|
CWE-601
Open Redirect
|
CVE-2024-45247
|
2024-10-8 02:47 |
2024-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307685
|
- |
|
-
|
-
|
Diebold Nixdorf – CWE-427: Uncontrolled Search Path Element
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2024-45246
|
2024-10-8 02:47 |
2024-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307686
|
- |
|
-
|
-
|
Diebold Nixdorf – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
|
CWE-200
Information Exposure
|
CVE-2024-45245
|
2024-10-8 02:47 |
2024-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307687
|
- |
|
-
|
-
|
A vulnerability was found in ESAFENET CDG V5. It has been rated as critical. Affected by this issue is some unknown functionality of the file /MultiServerBackService?path=1. The manipulation of the a…
|
CWE-89
SQL Injection
|
CVE-2024-9536
|
2024-10-8 02:47 |
2024-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307688
|
5.3 |
MEDIUM
Network
|
automattic
|
sensei_lms
|
The Sensei LMS WordPress plugin before 4.24.2 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak email templates.
|
NVD-CWE-noinfo
|
CVE-2024-7786
|
2024-10-8 02:46 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307689
|
4.3 |
MEDIUM
Network
|
snapshot_backup_project
|
snapshot_backup
|
The Snapshot Backup WordPress plugin through 2.1.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add St…
|
CWE-352
Origin Validation Error
|
CVE-2024-7689
|
2024-10-8 02:45 |
2024-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307690
|
4.3 |
MEDIUM
Network
|
azindex_project
|
azindex
|
The AZIndex WordPress plugin through 0.8.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS…
|
CWE-352
Origin Validation Error
|
CVE-2024-7687
|
2024-10-8 02:45 |
2024-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|