|
305871
|
8.8 |
HIGH
Network
|
darkmysite
|
darkmysite
|
Cross-Site Request Forgery (CSRF) vulnerability in DarkMySite DarkMySite – Advanced Dark Mode Plugin for WordPress darkmysite allows Cross Site Request Forgery.This issue affects DarkMySite – Advance…
|
CWE-352
Origin Validation Error
|
CVE-2024-50466
|
2024-11-7 08:13 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305872
|
5.3 |
MEDIUM
Network
|
openjsf
|
express
|
A vulnerability has been identified in the Express response.links function, allowing for arbitrary resource injection in the Link header when unsanitized data is used.
The issue arises from improper…
|
NVD-CWE-noinfo
|
CVE-2024-10491
|
2024-11-7 08:08 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305873
|
5.4 |
MEDIUM
Network
|
joshlobe
|
ultimate_tinymce
|
The Ultimate TinyMCE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'field' shortcode in all versions up to, and including, 5.7 due to insufficient input sanitization and o…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8627
|
2024-11-7 08:06 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305874
|
5.5 |
MEDIUM
Network
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sens…
|
CWE-611
XXE
|
CVE-2024-45086
|
2024-11-7 08:04 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305875
|
5.4 |
MEDIUM
Network
|
oracle
|
peoplesoft_enterprise_cost_center_common_application_objects
|
Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Activity Guide Composer). The supported version that is affected is 9.2. Easily exp…
|
NVD-CWE-noinfo
|
CVE-2024-21264
|
2024-11-7 07:56 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305876
|
5.3 |
MEDIUM
Network
|
oracle
|
installed_base
|
Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability a…
|
NVD-CWE-noinfo
|
CVE-2024-21258
|
2024-11-7 07:56 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305877
|
3.0 |
LOW
Adjacent
|
oracle
|
hyperion_bi\+
|
Vulnerability in the Oracle Hyperion BI+ product of Oracle Hyperion (component: UI and Visualization). The supported version that is affected is 11.2.18.0.000. Easily exploitable vulnerability allo…
|
NVD-CWE-noinfo
|
CVE-2024-21257
|
2024-11-7 07:55 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305878
|
8.1 |
HIGH
Network
|
oracle
|
process_manufacturing_product_development
|
Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Quality Manager Specification). Supported versions that are affected are 12.2.13-…
|
NVD-CWE-noinfo
|
CVE-2024-21250
|
2024-11-7 07:54 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305879
|
4.3 |
MEDIUM
Network
|
oracle
|
peoplesoft_enterprise_fin_expenses
|
Vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses). The supported version that is affected is 9.2. Easily exploitable vulnerability allows lo…
|
NVD-CWE-noinfo
|
CVE-2024-21249
|
2024-11-7 07:53 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305880
|
8.0 |
HIGH
Network
|
romadebrian
|
web-sekolah
|
A vulnerability classified as critical was found in romadebrian WEB-Sekolah 1.0. Affected by this vulnerability is an unknown functionality of the file /Proses_Kirim.php of the component Mail Handler…
|
CWE-89
SQL Injection
|
CVE-2024-10841
|
2024-11-7 07:50 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|