|
309061
|
6.1 |
MEDIUM
Network
|
icopydoc
|
yml_for_yandex_market
|
The YML for Yandex Market plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 4.7.2 due to insufficient input sanitizat…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9378
|
2024-10-8 05:15 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309062
|
4.8 |
MEDIUM
Network
|
redhat
|
build_of_keycloak
|
A vulnerability was found in Keycloak. Expired OTP codes are still usable when using FreeOTP when the OTP token period is set to 30 seconds (default). Instead of expiring and deemed unusable around 3…
|
CWE-324
Use of a Key Past its Expiration Date
|
CVE-2024-7318
|
2024-10-8 05:15 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309063
|
5.4 |
MEDIUM
Network
|
cisco
|
nexus_dashboard_fabric_controller nexus_dashboard
|
A vulnerability in the REST API endpoints of Cisco Nexus Dashboard could allow an authenticated, low-privileged, remote attacker to perform limited Administrator actions on an affected device.
Thi…
|
CWE-862
Missing Authorization
|
CVE-2024-20442
|
2024-10-8 05:11 |
2024-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309064
|
5.4 |
MEDIUM
Network
|
vowelweb
|
ibtana
|
The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ attribute within the 'wp:ive/ive-productscarousel' Gutenberg block in all vers…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8282
|
2024-10-8 05:11 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309065
|
6.5 |
MEDIUM
Adjacent
|
gotenna
|
atak_plugin
|
In the goTenna Pro ATAK Plugin application, the encryption keys are
stored along with a static IV on the device. This allows for complete
decryption of keys stored on the device. This allows an att…
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2024-43694
|
2024-10-8 04:40 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309066
|
- |
|
-
|
-
|
Syrotech SY-GOPON-8OLT-L3 v1.6.0_240629 was discovered to contain an authenticated command injection vulnerability.
|
-
|
CVE-2024-46658
|
2024-10-8 04:37 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309067
|
- |
|
-
|
-
|
Several CGI endpoints are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POST requests to the strcpy function on DrayTek Vigor…
|
-
|
CVE-2024-41590
|
2024-10-8 04:37 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309068
|
- |
|
-
|
-
|
The CGI endpoints v2x00.cgi and cgiwcg.cgi of DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters pa…
|
-
|
CVE-2024-41588
|
2024-10-8 04:37 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309069
|
- |
|
-
|
-
|
DrayTek Vigor3910 devices through 4.3.2.6 are affected by an OS command injection vulnerability that allows an attacker to leverage the recvCmd binary to escape from the emulated instance and inject …
|
-
|
CVE-2024-41585
|
2024-10-8 04:37 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309070
|
- |
|
-
|
-
|
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthenticated attacker to conduct an unauthorized access attack due to inadequate acc…
|
-
|
CVE-2024-42514
|
2024-10-8 04:37 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|