|
308331
|
4.8 |
MEDIUM
Network
|
wikimedia
|
apex
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Apex skin allows Stored XSS.This issue affects Mediaw…
|
CWE-79
Cross-site Scripting
|
CVE-2024-47840
|
2024-10-17 01:44 |
2024-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308332
|
8.8 |
HIGH
Network
|
dlink
|
dir-619l_firmware
|
A vulnerability was found in D-Link DIR-619L B1 2.06. It has been rated as critical. This issue affects the function formLogDnsquery of the file /goform/formLogDnsquery. The manipulation of the argum…
|
CWE-120
Classic Buffer Overflow
|
CVE-2024-9783
|
2024-10-17 01:43 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308333
|
6.1 |
MEDIUM
Network
|
mediawiki
|
cargo
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows Cross-Site Scripting (XSS).This issue af…
|
CWE-79
Cross-site Scripting
|
CVE-2024-47847
|
2024-10-17 01:42 |
2024-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308334
|
8.8 |
HIGH
Network
|
mediawiki
|
cargo
|
Cross-Site Request Forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows Cross Site Request Forgery.This issue affects Mediawiki - Cargo: from 3.6.X before 3.6.1.
|
CWE-352
Origin Validation Error
|
CVE-2024-47846
|
2024-10-17 01:42 |
2024-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308335
|
- |
|
-
|
-
|
On Microchip RN4870 devices, when more than one consecutive PairReqNoInputNoOutput request is
received, the device becomes incapable of completing the pairing
process. A third party can inject a se…
|
-
|
CVE-2024-29155
|
2024-10-17 01:38 |
2024-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308336
|
- |
|
-
|
-
|
Docker Desktop before v4.34.3 allows RCE via unsanitized GitHub source link in Build view.
|
-
|
CVE-2024-9348
|
2024-10-17 01:38 |
2024-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308337
|
- |
|
-
|
-
|
A Reflected Cross Site Scripting (XSS) vulnerability was found in /trms/listed- teachers.php in PHPGurukul Teachers Record Management System v2.1, which allows remote attackers to execute arbitrary c…
|
-
|
CVE-2024-48744
|
2024-10-17 01:38 |
2024-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308338
|
- |
|
-
|
-
|
A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Configuration utility that allows an attacker with the Administrator role to run JavaScript in the contex…
|
-
|
CVE-2024-47139
|
2024-10-17 01:38 |
2024-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308339
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.1.14. This is due to insufficient verification on the user being retur…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2024-9893
|
2024-10-17 01:38 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308340
|
- |
|
-
|
-
|
Relative Path Traversal vulnerability in James Park Analyse Uploads allows Relative Path Traversal.This issue affects Analyse Uploads: from n/a through 0.5.
|
CWE-23
Relative Path Traversal
|
CVE-2024-49253
|
2024-10-17 01:38 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|