|
306991
|
9.8 |
CRITICAL
Network
|
magicbug
|
cloudlog
|
Cloudlog 2.6.15 allows Oqrs.php get_station_info station_id SQL injection.
|
CWE-89
SQL Injection
|
CVE-2024-48255
|
2024-10-16 23:26 |
2024-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306992
|
6.1 |
MEDIUM
Network
|
nerdpress
|
smart_custom_404_error_page
|
The Smart Custom 404 Error Page plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_SERVER['REQUEST_URI'] in all versions up to, and including, 11.4.7 due to insufficient input…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9204
|
2024-10-16 23:26 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306993
|
9.8 |
CRITICAL
Network
|
wavelog
|
wavelog
|
Wavelog 1.8.5 allows Oqrs_model.php get_worked_modes station_id SQL injectioin.
|
CWE-89
SQL Injection
|
CVE-2024-48257
|
2024-10-16 23:24 |
2024-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306994
|
8.8 |
HIGH
Network
|
dlink
|
dir-619l_firmware
|
A vulnerability classified as critical has been found in D-Link DIR-619L B1 2.06. Affected is the function formResetStatistic of the file /goform/formResetStatistic. The manipulation of the argument …
|
CWE-120
Classic Buffer Overflow
|
CVE-2024-9784
|
2024-10-16 23:12 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306995
|
8.1 |
HIGH
Network
|
shilpisoft
|
client_dashboard
|
This vulnerability exists in Shilpi Client Dashboard due to implementation of inadequate authentication mechanism in the login module wherein access to any users account is granted with just their co…
|
NVD-CWE-Other
|
CVE-2024-47652
|
2024-10-16 23:12 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306996
|
5.7 |
MEDIUM
Network
|
enalean
|
tuleap
|
Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.40, Tuleap Enterprise Edition 15.13-3, and Tuleap Enterprise Edition 15…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2024-46988
|
2024-10-16 23:07 |
2024-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306997
|
5.4 |
MEDIUM
Network
|
ultimatemember
|
ultimate_member
|
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's '…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8519
|
2024-10-16 23:06 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306998
|
4.8 |
MEDIUM
Network
|
enalean
|
tuleap
|
Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.37, Tuleap Enterprise Edition 15.13-3, and Tuleap Enterprise Edition 15…
|
CWE-79
Cross-site Scripting
|
CVE-2024-46980
|
2024-10-16 23:05 |
2024-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306999
|
7.5 |
HIGH
Network
|
acronis
|
cyber_protect
|
Cleartext transmission of sensitive information in acep-collector service. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2024-49387
|
2024-10-16 22:58 |
2024-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307000
|
9.1 |
CRITICAL
Network
|
acronis
|
cyber_protect
|
Sensitive information manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-49388
|
2024-10-16 22:57 |
2024-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|