|
308411
|
5.4 |
MEDIUM
Network
|
acquia
|
mautic
|
Prior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report.
|
CWE-79
Cross-site Scripting
|
CVE-2021-27917
|
2024-09-28 00:13 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308412
|
- |
|
-
|
-
|
WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the Apache Ant script functionality.
|
-
|
CVE-2024-37779
|
2024-09-27 23:35 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308413
|
5.4 |
MEDIUM
Network
|
happyforms
|
happyforms
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Happyforms allows Stored XSS.This issue affects Happyforms: from n/a through 1.26.0.
|
CWE-79
Cross-site Scripting
|
CVE-2024-44063
|
2024-09-27 23:31 |
2024-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308414
|
7.2 |
HIGH
Network
|
purestorage
|
purity\/\/fa
|
A condition exists in FlashArray Purity whereby an user with array admin role can execute arbitrary commands remotely to escalate privilege on the array.
|
CWE-94
Code Injection
|
CVE-2024-0004
|
2024-09-27 23:24 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308415
|
7.2 |
HIGH
Network
|
purestorage
|
purity\/\/fa
|
A condition exists in FlashArray Purity whereby a malicious user could use a remote administrative service to create an account on the array allowing privileged access.
|
NVD-CWE-noinfo
|
CVE-2024-0003
|
2024-09-27 23:23 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308416
|
9.8 |
CRITICAL
Network
|
purestorage
|
purity\/\/fa
|
A condition exists in FlashArray Purity whereby an attacker can employ a privileged account allowing remote access to the array.
|
NVD-CWE-noinfo
|
CVE-2024-0002
|
2024-09-27 23:13 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308417
|
9.8 |
CRITICAL
Network
|
purestorage
|
purity\/\/fa
|
A condition exists in FlashArray Purity whereby a local account intended for initial array configuration remains active potentially allowing a malicious actor to gain elevated privileges.
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2024-0001
|
2024-09-27 23:08 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308418
|
6.1 |
MEDIUM
Network
|
jenniferhall
|
filmix
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jennifer Hall Filmix allows Reflected XSS.This issue affects Filmix: from n/a through 1.1.
|
CWE-79
Cross-site Scripting
|
CVE-2024-44060
|
2024-09-27 23:04 |
2024-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308419
|
6.1 |
MEDIUM
Network
|
averta
|
phlox
|
The Phlox PRO theme for WordPress is vulnerable to Reflected Cross-Site Scripting via search parameters in all versions up to, and including, 5.16.4 due to insufficient input sanitization and output …
|
CWE-79
Cross-site Scripting
|
CVE-2024-6339
|
2024-09-27 23:04 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308420
|
6.1 |
MEDIUM
Network
|
wpbookingsystem
|
wp_booking_system
|
The WP Booking System – Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the UR…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8797
|
2024-09-27 23:02 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|