|
309491
|
6.5 |
MEDIUM
Network
|
mmrs151
|
daily_prayer_time
|
The Daily Prayer Time plugin for WordPress is vulnerable to SQL Injection via the 'max_word' attribute of the 'quran_verse' shortcode in all versions up to, and including, 2024.08.26 due to insuffici…
|
CWE-89
SQL Injection
|
CVE-2024-8621
|
2024-10-3 01:10 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309492
|
6.1 |
MEDIUM
Network
|
xtendify
|
simple_calendar
|
The Simple Calendar – Google Calendar Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versio…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8549
|
2024-10-3 01:04 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309493
|
6.1 |
MEDIUM
Network
|
ellevo
|
ellevo
|
A reflected cross-site scripting (XSS) vulnerability in Ellevo 6.2.0.38160 allows attackers to execute arbitrary code in the context of a user's browser via a crafted payload or URL.
|
CWE-79
Cross-site Scripting
|
CVE-2024-46655
|
2024-10-3 00:40 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309494
|
5.3 |
MEDIUM
Adjacent
|
synology
|
active_backup_for_business_agent
|
Missing encryption of sensitive data vulnerability in login component in Synology Active Backup for Business Agent before 2.7.0-3221 allows adjacent man-in-the-middle attackers to obtain user credent…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2023-52950
|
2024-10-3 00:26 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309495
|
5.5 |
MEDIUM
Local
|
synology
|
active_backup_for_business_agent
|
Missing authentication for critical function vulnerability in proxy settings functionality in Synology Active Backup for Business Agent before 2.7.0-3221 allows local users to obtain user credential …
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2023-52949
|
2024-10-3 00:26 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309496
|
5.0 |
MEDIUM
Local
|
synology
|
active_backup_for_business_agent
|
Missing encryption of sensitive data vulnerability in settings functionality in Synology Active Backup for Business Agent before 2.7.0-3221 allows local users to obtain user credential via unspecifie…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2023-52948
|
2024-10-3 00:26 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309497
|
3.3 |
LOW
Local
|
synology
|
active_backup_for_business_agent
|
Missing authentication for critical function vulnerability in logout functionality in Synology Active Backup for Business Agent before 2.6.3-3101 allows local users to logout the client via unspecifi…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2023-52947
|
2024-10-3 00:26 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309498
|
5.5 |
MEDIUM
Local
|
opentext
|
identity_manager_azuread_driver
|
A vulnerability identified in OpenText™
Identity Manager AzureAD Driver that allows logging of sensitive information into log file. This impacts all versions before 5.1.4.0
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2021-22518
|
2024-10-3 00:10 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309499
|
7.5 |
HIGH
Network
|
netiq
|
identity_manager_rest_driver
|
Possible Insertion of Sensitive Information into Log File Vulnerability
in Identity Manager has been discovered in
OpenText™
Identity Manager REST Driver. This impact version before 1.1.2.0200.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2022-26322
|
2024-10-3 00:03 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309500
|
9.8 |
CRITICAL
Network
|
rockwellautomation
|
factorytalk_batch_view
|
CVE-2024-45823 IMPACT
An
authentication bypass vulnerability exists in the affected product. The
vulnerability exists due to shared secrets across accounts and could allow a threat
actor to impers…
|
NVD-CWE-noinfo
|
CVE-2024-45823
|
2024-10-2 23:49 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|