|
307071
|
- |
|
-
|
-
|
Neye3C v4.5.2.0 was discovered to contain a hardcoded encryption key in the firmware update mechanism.
|
-
|
CVE-2024-48539
|
2024-10-25 21:56 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307072
|
- |
|
-
|
-
|
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. A person with physical access to an unlocked Mac may be able to gain root code execution.
|
-
|
CVE-2024-44141
|
2024-10-25 21:56 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307073
|
- |
|
-
|
-
|
Incorrect access control in the firmware update and download processes of Neye3C v4.5.2.0 allows attackers to access sensitive information by analyzing the code and data within the APK file.
|
-
|
CVE-2024-48538
|
2024-10-25 21:56 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307074
|
- |
|
-
|
-
|
A Cross-Site Scripting vulnerability has been found in Janto v4.3r11 from Impronta. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a ma…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10332
|
2024-10-25 21:56 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307075
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Contact Form 7 – Repeatable Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's field_group shortcode in all versions up to, and including, 2.0.1 due to insu…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10180
|
2024-10-25 21:56 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307076
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The WP Adminify – Custom WordPress Dashboard, Login and Admin Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4…
|
-
|
CVE-2024-8959
|
2024-10-25 21:56 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307077
|
- |
|
-
|
-
|
Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in the technician reports feature.
|
-
|
CVE-2024-5608
|
2024-10-25 21:56 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307078
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tooltip’ parameter in all versions up to, and including, 9.6.1 due to insufficient input sanitization an…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9650
|
2024-10-25 21:56 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307079
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Extra Product Options Builder for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'RednaoSerializedFields' parameter during the creation of a signature file …
|
CWE-79
Cross-site Scripting
|
CVE-2024-9214
|
2024-10-25 21:56 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307080
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Compact WP Audio Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's
sc_embed_player shortcode in all versions up to, and including, 1.9.13 due to insuffic…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10176
|
2024-10-25 21:56 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|