|
306721
|
8.8 |
HIGH
Network
|
mediawiki
|
cargo
|
Cross-Site Request Forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows Cross Site Request Forgery.This issue affects Mediawiki - Cargo: from 3.6.X before 3.6.1.
|
CWE-352
Origin Validation Error
|
CVE-2024-47846
|
2024-10-17 01:42 |
2024-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306722
|
- |
|
-
|
-
|
On Microchip RN4870 devices, when more than one consecutive PairReqNoInputNoOutput request is
received, the device becomes incapable of completing the pairing
process. A third party can inject a se…
|
-
|
CVE-2024-29155
|
2024-10-17 01:38 |
2024-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306723
|
- |
|
-
|
-
|
Docker Desktop before v4.34.3 allows RCE via unsanitized GitHub source link in Build view.
|
-
|
CVE-2024-9348
|
2024-10-17 01:38 |
2024-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306724
|
- |
|
-
|
-
|
A Reflected Cross Site Scripting (XSS) vulnerability was found in /trms/listed- teachers.php in PHPGurukul Teachers Record Management System v2.1, which allows remote attackers to execute arbitrary c…
|
-
|
CVE-2024-48744
|
2024-10-17 01:38 |
2024-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306725
|
- |
|
-
|
-
|
A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Configuration utility that allows an attacker with the Administrator role to run JavaScript in the contex…
|
-
|
CVE-2024-47139
|
2024-10-17 01:38 |
2024-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306726
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.1.14. This is due to insufficient verification on the user being retur…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2024-9893
|
2024-10-17 01:38 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306727
|
- |
|
-
|
-
|
Relative Path Traversal vulnerability in James Park Analyse Uploads allows Relative Path Traversal.This issue affects Analyse Uploads: from n/a through 0.5.
|
CWE-23
Relative Path Traversal
|
CVE-2024-49253
|
2024-10-17 01:38 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306728
|
- |
|
-
|
-
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ahime Ahime Image Printer.This issue affects Ahime Image Printer: from n/a through 1.0.0.
|
CWE-22
Path Traversal
|
CVE-2024-49245
|
2024-10-17 01:38 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306729
|
- |
|
-
|
-
|
Unrestricted Upload of File with Dangerous Type vulnerability in Shafiq Digital Lottery allows Upload a Web Shell to a Web Server.This issue affects Digital Lottery: from n/a through 3.0.5.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-49242
|
2024-10-17 01:38 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306730
|
- |
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in Innovaweb Sp. Z o.O. Free Stock Photos Foter allows Object Injection.This issue affects Free Stock Photos Foter: from n/a through 1.5.4.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-49227
|
2024-10-17 01:38 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|