6.9

CVSS4.0

CVE-2024-10335 - SourceCodester Garbage Collection Management System login.php sql injection

A vulnerability was found in SourceCodester Garbage Collection Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The…

πŸ“… Published: Oct. 24, 2024, 4:31 p.m. πŸ”„ Last Modified: Nov. 7, 2024, 6:52 p.m.

6.9

CVSS4.0

CVE-2024-9692 - Improper Access Control in Input in VIMESA VHF/FM Transmitter Blue Plus

VIMESA VHF/FM Transmitter Blue Plus is suffering from a Denial-of-Service (DoS) vulnerability. An unauthenticated attacker can issue an unauthorized HTTP GET request to the unprotected endpoint 'doreboot' and restart the transmitter operations.

πŸ“… Published: Oct. 24, 2024, 4:20 p.m. πŸ”„ Last Modified: Oct. 25, 2024, 12:56 p.m.

0.0

CVE-2024-10347 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: Oct. 24, 2024, 3:01 p.m. πŸ”„ Last Modified: Feb. 11, 2025, 2:15 a.m.

6.1

CVSS3.1

CVE-2024-45031 - Apache Syncope: Stored XSS in Console and Enduser

When editing objects in the Syncope Console, incomplete HTML tags could be used to bypass HTML sanitization. This made it possible to inject stored XSS payloads which would trigger for other users during ordinary usage of the application. XSS payloads could also be injected in Syncope Enduser when …

πŸ“… Published: Oct. 24, 2024, 2:21 p.m. πŸ”„ Last Modified: Sept. 29, 2025, 9:48 p.m.

5.4

CVSS3.1

CVE-2024-49693 - WordPress Mega Elements – Addons for Elementor plugin <= 1.2.6 - Cross Site Scripting (XSS) vulnera…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kraft Plugins Mega Elements mega-elements-addons-for-elementor allows Stored XSS.This issue affects Mega Elements: from n/a through <= 1.2.6.

πŸ“… Published: Oct. 24, 2024, 12:41 p.m. πŸ”„ Last Modified: April 1, 2026, 4:18 p.m.

5.4

CVSS3.1

CVE-2024-49695 - WordPress WP Flow Plus plugin <= 5.2.3 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins WP Flow Plus wp-imageflow2 allows Stored XSS.This issue affects WP Flow Plus: from n/a through <= 5.2.3.

πŸ“… Published: Oct. 24, 2024, 12:38 p.m. πŸ”„ Last Modified: April 1, 2026, 4:18 p.m.

6.4

CVSS3.1

CVE-2024-10180 - Contact Form 7 - Repeatable Fields <= 2.0.1 - Authenticated (Contributor+) Stored Cross-Site Script…

The Contact Form 7 – Repeatable Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's field_group shortcode in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible …

πŸ“… Published: Oct. 24, 2024, 12:32 p.m. πŸ”„ Last Modified: April 8, 2026, 4:34 p.m.

4.8

CVSS3.1

CVE-2024-49696 - WordPress Photo Gallery, Images, Slider in Rbs Image Gallery plugin <= 3.2.21 - Cross Site Scriptin…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robosoft Robo Gallery robo-gallery allows Stored XSS.This issue affects Robo Gallery: from n/a through <= 3.2.21.

πŸ“… Published: Oct. 24, 2024, 12:29 p.m. πŸ”„ Last Modified: April 1, 2026, 4:18 p.m.

5.4

CVSS3.1

CVE-2024-49702 - WordPress myCred Elementor plugin <= 1.2.6 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal myCred Elementor mycred-for-elementor allows Stored XSS.This issue affects myCred Elementor: from n/a through <= 1.2.6.

πŸ“… Published: Oct. 24, 2024, 12:28 p.m. πŸ”„ Last Modified: April 1, 2026, 4:18 p.m.

6.1

CVSS3.1

CVE-2024-10332 -

A Cross-Site Scripting vulnerability has been found in Janto v4.3r11 from Impronta. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the endpoint β€œ/abonados/public/janto/main.php”.

πŸ“… Published: Oct. 24, 2024, 12:14 p.m. πŸ”„ Last Modified: Oct. 25, 2024, 12:56 p.m.
Total resulsts: 343740
Page 7611 of 34,374
Β« previous page Β» next page
Filters