|
307881
|
8.8 |
HIGH
Network
|
ninjaforms
|
ninja_forms
|
Cross-Site Request Forgery (CSRF) vulnerability in Saturday Drive Ninja Forms allows Cross Site Request Forgery.This issue affects Ninja Forms: from n/a through 3.8.6.
|
CWE-352
Origin Validation Error
|
CVE-2024-39628
|
2024-10-20 21:15 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307882
|
4.3 |
MEDIUM
Network
|
discourse
|
discourse
|
Discourse is an open source platform for community discussion. A user can create a post with many replies, and then attempt to fetch them all at once. This can potentially reduce the availability of …
|
NVD-CWE-noinfo
|
CVE-2024-43789
|
2024-10-19 10:13 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307883
|
8.2 |
HIGH
Network
|
discourse
|
discourse
|
Discourse is an open source platform for community discussion. A maliciously crafted email address could allow an attacker to bypass domain-based restrictions and gain access to private sites, catego…
|
NVD-CWE-noinfo
|
CVE-2024-45051
|
2024-10-19 10:11 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307884
|
4.3 |
MEDIUM
Network
|
discourse
|
discourse
|
Discourse is an open source platform for community discussion. Users can see topics with a hidden tag if they know the label/name of that tag. This issue has been patched in the latest stable, beta a…
|
NVD-CWE-noinfo
|
CVE-2024-45297
|
2024-10-19 10:06 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307885
|
6.1 |
MEDIUM
Network
|
discourse
|
discourse
|
Discourse is an open source platform for community discussion. An attacker can execute arbitrary JavaScript on users' browsers by sending a maliciously crafted chat message and replying to it. This i…
|
CWE-79
Cross-site Scripting
|
CVE-2024-47772
|
2024-10-19 09:58 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307886
|
5.4 |
MEDIUM
Network
|
newtype
|
webeip
|
NewType WebEIP v3.0 does not properly validate user input, allowing a remote attacker with regular privileges to insert JavaScript into specific parameters, resulting in a Reflected Cross-site Script…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9969
|
2024-10-19 09:51 |
2024-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307887
|
4.9 |
MEDIUM
Network
|
usualtool
|
usualtoolcms
|
A vulnerability, which was classified as critical, was found in HuangDou UTCMS V9. This affects an unknown part of the file app/modules/ut-template/admin/template_creat.php. The manipulation of the a…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-9917
|
2024-10-19 09:49 |
2024-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307888
|
7.2 |
HIGH
Network
|
usualtool
|
usualtoolcms
|
A vulnerability has been found in HuangDou UTCMS V9 and classified as critical. This vulnerability affects the function RunSql of the file app/modules/ut-data/admin/sql.php. The manipulation of the a…
|
CWE-89
SQL Injection
|
CVE-2024-9918
|
2024-10-19 09:47 |
2024-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307889
|
7.5 |
HIGH
Network
|
dueclic
|
wp_2fa_with_telegram
|
The WP 2FA with Telegram plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and including, 3.0. This is due to the two-factor code being stored in a cookie, whi…
|
CWE-565
Reliance on Cookies without Validation and Integrity Checking
|
CVE-2024-9820
|
2024-10-19 09:44 |
2024-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307890
|
8.8 |
HIGH
Network
|
newtype
|
webeip
|
WebEIP v3.0 from
NewType does not properly validate user input, allowing remote attackers with regular privilege to inject SQL commands to read, modify, and delete data stored in database. The affe…
|
CWE-89
SQL Injection
|
CVE-2024-9968
|
2024-10-19 09:42 |
2024-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|