|
306551
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10367
|
2024-11-1 21:57 |
2024-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306552
|
6.1 |
MEDIUM
Network
|
-
|
-
|
IDExpert from CHANGING Information Technology does not properly validate a parameter for a specific functionality, allowing unauthenticated remote attackers to inject JavsScript code and perform Refl…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10652
|
2024-11-1 21:57 |
2024-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306553
|
4.9 |
MEDIUM
Network
|
-
|
-
|
IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator interface, allowing remote attackers with administrator privileges to exploit this v…
|
CWE-36
Absolute Path Traversal
|
CVE-2024-10651
|
2024-11-1 21:57 |
2024-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306554
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Group Chat & Video Chat by AtomChat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's atomchat shortcode in all versions up to, and including, 1.1.5 due to insuff…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10232
|
2024-11-1 21:57 |
2024-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306555
|
- |
|
-
|
-
|
A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. Affected by this vulnerability is the function delFile/delDifferCourseList of the file /com/esafenet/servlet/ajax/Public…
|
CWE-89
SQL Injection
|
CVE-2024-10595
|
2024-11-1 21:57 |
2024-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306556
|
- |
|
-
|
-
|
Qualitor v8.24 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /request/viewValidacao.php.
|
-
|
CVE-2024-48360
|
2024-11-1 21:57 |
2024-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306557
|
- |
|
-
|
-
|
Qualitor v8.24 was discovered to contain a remote code execution (RCE) vulnerability via the gridValoresPopHidden parameter.
|
-
|
CVE-2024-48359
|
2024-11-1 21:57 |
2024-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306558
|
- |
|
-
|
-
|
An Insecure Direct Object Reference (IDOR) vulnerability in appointment-detail.php in Phpgurukul's Beauty Parlour Management System v1.1 allows unauthorized access to the Personally Identifiable Info…
|
-
|
CVE-2024-51066
|
2024-11-1 21:57 |
2024-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306559
|
- |
|
-
|
-
|
Studio-42 eLfinder 2.1.62 contains a filename restriction bypass leading to a persistent Cross-site Scripting (XSS) vulnerability.
|
-
|
CVE-2023-52045
|
2024-11-1 21:57 |
2024-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306560
|
- |
|
-
|
-
|
Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. Prior to 1.4.0, there is an issue where verification signatures for requests sent to Reverb's Pusher-comp…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2024-50347
|
2024-11-1 21:57 |
2024-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|