|
307321
|
6.1 |
MEDIUM
Network
|
heateor
|
sassy_social_share
|
The Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'urls' parameter called via the 'heateor_sss_sharing_count' AJAX action in versions up to, and incl…
|
CWE-79
Cross-site Scripting
|
CVE-2022-4971
|
2024-10-31 01:37 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307322
|
7.5 |
HIGH
Network
|
apple
|
macos
|
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura 13.7.1, macOS Sonoma 14.7.1. An app may be able to read sensitive location inf…
|
NVD-CWE-noinfo
|
CVE-2024-44289
|
2024-10-31 01:35 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307323
|
- |
|
-
|
-
|
A logic issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.7.1, macOS Sonoma 14.7.1. A sandboxed process may be able to circumvent sandbox restrictions.
|
-
|
CVE-2024-44270
|
2024-10-31 01:35 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307324
|
- |
|
-
|
-
|
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.1, macOS Sonoma 14.7.1. A malicious application may be able to modify protected parts of the file system.
|
-
|
CVE-2024-44267
|
2024-10-31 01:35 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307325
|
- |
|
-
|
-
|
A path handling issue was addressed with improved logic. This issue is fixed in visionOS 2.1, iOS 18.1 and iPadOS 18.1, macOS Ventura 13.7.1, macOS Sonoma 14.7.1, watchOS 11.1, tvOS 18.1. A malicious…
|
-
|
CVE-2024-44255
|
2024-10-31 01:35 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307326
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15. An attacker may be able to view restricted content from the lock screen.
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2024-44174
|
2024-10-31 01:35 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307327
|
3.3 |
LOW
Local
|
apple
|
macos
|
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. A malicious app may be able to change network settings.
|
NVD-CWE-noinfo
|
CVE-2024-40792
|
2024-10-31 01:35 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307328
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in FedCM in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
|
NVD-CWE-noinfo
|
CVE-2024-7976
|
2024-10-31 01:35 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307329
|
7.5 |
HIGH
Network
|
wpchill
|
download_monitor
|
The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related to reporting in versions up to, and including, 4.7…
|
CWE-862
Missing Authorization
|
CVE-2022-4972
|
2024-10-31 01:34 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307330
|
4.9 |
MEDIUM
Network
|
mayurik
|
petrol_pump_management
|
A vulnerability classified as critical was found in SourceCodester Petrol Pump Management Software 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/print.php. The ma…
|
CWE-89
SQL Injection
|
CVE-2024-10354
|
2024-10-31 01:32 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|