|
308641
|
- |
|
-
|
-
|
An issue was discovered in GitLab EE affecting all versions starting from 12.5 prior to 17.2.9, starting from 17.3, prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows running pipel…
|
-
|
CVE-2024-9164
|
2024-10-15 21:58 |
2024-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308642
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The WP Ultimate Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpupg-grid-with-filters shortcode in all versions up to, and including, 3.9.3 due to insuf…
|
-
|
CVE-2024-9051
|
2024-10-15 21:58 |
2024-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308643
|
- |
|
-
|
-
|
An issue was discovered in GitLab CE/EE affecting all versions starting from 11.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows an attacker…
|
-
|
CVE-2024-8970
|
2024-10-15 21:58 |
2024-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308644
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and i…
|
CWE-200
Information Exposure
|
CVE-2024-8913
|
2024-10-15 21:58 |
2024-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308645
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The WordPress Comments Import & Export plugin for WordPress is vulnerable to to arbitrary file read due to insufficient file path validation during the comments import process, in versions up to, and…
|
CWE-22
Path Traversal
|
CVE-2024-7514
|
2024-10-15 21:58 |
2024-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308646
|
- |
|
-
|
-
|
A path traversal vulnerability exists in the parisneo/lollms-webui repository, specifically in the `lollms_file_system.py` file. The functions `add_rag_database`, `toggle_mount_rag_database`, and `ve…
|
CWE-22
Path Traversal
|
CVE-2024-6971
|
2024-10-15 21:58 |
2024-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308647
|
- |
|
-
|
-
|
An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 11.4 before 17.2.9, all versions starting from 17.3 before 17.3.5, all versions starting from 17.4 before …
|
-
|
CVE-2024-5005
|
2024-10-15 21:58 |
2024-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308648
|
- |
|
-
|
-
|
Snipe-IT before 7.0.10 allows remote code execution (associated with cookie serialization) when an attacker knows the APP_KEY. This is exacerbated by .env files, available from the product's reposito…
|
-
|
CVE-2024-48987
|
2024-10-15 21:58 |
2024-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308649
|
- |
|
-
|
-
|
A Server-Side Request Forgery (SSRF) vulnerability in SMA1000 appliance firmware versions 12.4.3-02676 and earlier allows a remote, unauthenticated attacker to cause the SMA1000 server-side applicati…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-45317
|
2024-10-15 21:58 |
2024-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308650
|
- |
|
-
|
-
|
The Improper link resolution before file access ('Link Following') vulnerability in SonicWall Connect Tunnel (version 12.4.3.271 and earlier of Windows client) allows users with standard privileges t…
|
CWE-59
Link Following
|
CVE-2024-45316
|
2024-10-15 21:58 |
2024-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|