|
310081
|
8.8 |
HIGH
Network
|
external-secrets
|
external_secrets_operator
|
External Secrets Operator is a Kubernetes operator that integrates external secret management systems. The external-secrets has a deployment called default-external-secrets-cert-controller, which is …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2024-45041
|
2024-09-19 02:31 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310082
|
9.8 |
CRITICAL
Network
|
angeljudesuarez
|
tailoring_management_system
|
A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulnerability is an unknown functionality of the file ssms.php. The manipulation of …
|
CWE-89
SQL Injection
|
CVE-2024-8611
|
2024-09-19 02:24 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310083
|
7.8 |
HIGH
Local
|
ivanti
|
workspace_control
|
DLL hijacking in the management console of Ivanti Workspace Control version 10.18.0.0 and below allows a local authenticated attacker to escalate their privileges.
|
CWE-426
Untrusted Search Path
|
CVE-2024-44103
|
2024-09-19 02:18 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310084
|
6.1 |
MEDIUM
Network
|
teleogistic
|
invite_anyone
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Boone Gorges Invite Anyone allows Reflected XSS.This issue affects Invite Anyone: from n/a…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43327
|
2024-09-19 02:07 |
2024-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310085
|
4.8 |
MEDIUM
Network
|
starkdigital
|
wp_testimonial_widget
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Stark Digital WP Testimonial Widget allows Stored XSS.This issue affects WP Testimonial Wi…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43967
|
2024-09-19 02:00 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310086
|
8.8 |
HIGH
Network
|
thimpress
|
learnpress
|
Cross-Site Request Forgery (CSRF) vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.6.8.2.
|
CWE-352
Origin Validation Error
|
CVE-2024-39641
|
2024-09-19 01:57 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310087
|
8.8 |
HIGH
Network
|
themeum
|
tutor_lms
|
Cross-Site Request Forgery (CSRF) vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.7.2.
|
CWE-352
Origin Validation Error
|
CVE-2024-39645
|
2024-09-19 01:46 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310088
|
8.8 |
HIGH
Network
|
sender
|
sender
|
Cross-Site Request Forgery (CSRF) vulnerability in Sender Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce.This issue affects Sender – Newsletter, SMS and Email Marketing Autom…
|
CWE-352
Origin Validation Error
|
CVE-2024-39657
|
2024-09-19 01:25 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310089
|
8.8 |
HIGH
Network
|
10up
|
simple_local_avatars
|
Cross-Site Request Forgery (CSRF) vulnerability in 10up Simple Local Avatars.This issue affects Simple Local Avatars: from n/a through 2.7.10.
|
CWE-352
Origin Validation Error
|
CVE-2024-43116
|
2024-09-19 01:22 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310090
|
8.8 |
HIGH
Network
|
loftware
|
spectrum
|
Loftware Spectrum before 4.6 HF14 allows authenticated XXE attacks.
|
CWE-611
XXE
|
CVE-2023-37233
|
2024-09-19 01:10 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|