|
308881
|
5.4 |
MEDIUM
Network
|
hyumika
|
openstreetmap
|
The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's osm_map and osm_map_v3 shortcodes in all versions up to, and including, 6.1.0 due to insuffi…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8991
|
2024-10-5 03:56 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308882
|
5.4 |
MEDIUM
Network
|
fastlinemedia
|
beaver_builder
|
The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button Group module in all versions up to, and including, 2.8.3.6 due to…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9049
|
2024-10-5 03:53 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308883
|
4.3 |
MEDIUM
Network
|
bg5sbk
|
minicms
|
A vulnerability was found in bg5sbk MiniCMS 1.11. It has been classified as problematic. Affected is an unknown function of the file page-edit.php. The manipulation leads to cross-site request forger…
|
CWE-352
Origin Validation Error
|
CVE-2024-9282
|
2024-10-5 03:33 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308884
|
7.5 |
HIGH
Network
|
amirraminfar
|
dozzle
|
Dozzle is a realtime log viewer for docker containers. Before version 8.5.3, the app uses sha-256 as the hash for passwords, which leaves users susceptible to rainbow table attacks. The app switches …
|
CWE-326
Inadequate Encryption Strength
|
CVE-2024-47182
|
2024-10-5 03:31 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308885
|
8.2 |
HIGH
Network
|
openpetra
|
openpetra
|
Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMCommon.asmx function.
|
CWE-79
Cross-site Scripting
|
CVE-2024-40510
|
2024-10-5 03:28 |
2024-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308886
|
8.8 |
HIGH
Network
|
themewinter
|
eventin
|
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.8 via multiple style paramete…
|
CWE-22
Path Traversal
|
CVE-2024-7149
|
2024-10-5 03:23 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308887
|
4.8 |
MEDIUM
Network
|
ampache
|
ampache
|
Ampache is a web based audio/video streaming application and file manager. Prior to version 6.6.0, the Democratic Playlist Name is vulnerable to a stored cross-site scripting. Version 6.6.0 fixes thi…
|
CWE-79
Cross-site Scripting
|
CVE-2024-47184
|
2024-10-5 03:19 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308888
|
4.3 |
MEDIUM
Network
|
bg5sbk
|
minicms
|
A vulnerability was found in bg5sbk MiniCMS up to 1.11 and classified as problematic. This issue affects some unknown processing of the file post-edit.php. The manipulation leads to cross-site reques…
|
CWE-352
Origin Validation Error
|
CVE-2024-9281
|
2024-10-5 03:15 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308889
|
9.8 |
CRITICAL
Network
|
kvf-admin_project
|
kvf-admin
|
A vulnerability has been found in kalvinGit kvf-admin up to f12a94dc1ebb7d1c51ee978a85e4c7ed75c620ff and classified as critical. This vulnerability affects the function fileUpload of the file FileUpl…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-9280
|
2024-10-5 03:00 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308890
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Add array index check for hdcp ddc access
[Why]
Coverity reports OVERRUN warning. Do not check if array
index va…
|
CWE-129
Improper Validation of Array Index
|
CVE-2024-46804
|
2024-10-5 02:51 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|