|
309641
|
- |
|
-
|
-
|
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1 and 9.5.x <= 9.5.9 fail to prevent detailed error messages from being displayed in Playbooks which allows an attacker to generate a large respon…
|
-
|
CVE-2024-47401
|
2024-10-29 18:15 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309642
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Post Status Notifier Lite and Premium plugins for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in all versions up to, and including, 1.11.6 due to insufficie…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10048
|
2024-10-29 18:15 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309643
|
- |
|
-
|
-
|
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to check that the origin of the message in an integration action matches with the original post metadata which allows an au…
|
-
|
CVE-2024-50052
|
2024-10-29 17:15 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309644
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.4 via the render function in elements/tabs/tabs.php. …
|
CWE-200
Information Exposure
|
CVE-2024-10312
|
2024-10-29 17:15 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309645
|
- |
|
-
|
-
|
Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled which allows a user to get private channel names by using cmd+K/ctrl+K.
|
-
|
CVE-2024-10241
|
2024-10-29 17:15 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309646
|
8.8 |
HIGH
Network
|
-
|
-
|
The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to unauthorized user profile modification due to missing authorization checks on the /wp-json/…
|
CWE-862
Missing Authorization
|
CVE-2024-10008
|
2024-10-29 15:15 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309647
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the question's content parameter in all versions up to, and…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10000
|
2024-10-29 15:15 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309648
|
- |
|
-
|
-
|
There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authenticated attacker could use the vulnerability to exe…
|
-
|
CVE-2024-22065
|
2024-10-29 11:15 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309649
|
- |
|
-
|
-
|
A vulnerability, which was classified as problematic, was found in LinZhaoguan pb-cms up to 2.0.1. Affected is an unknown function of the file /admin#themes of the component Theme Management Module. …
|
CWE-79
Cross-site Scripting
|
CVE-2024-10479
|
2024-10-29 11:15 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309650
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
-
|
CVE-2024-43885
|
2024-10-29 11:15 |
2024-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|