6.9

CVSS4.0

CVE-2024-10336 - SourceCodeHero Clothes Recommendation System Admin Login Page index.php sql injection

A vulnerability was found in SourceCodeHero Clothes Recommendation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/index.php of the component Admin Login Page. The manipulation of the argument t1 leads to sql injection. The attack may be init…

πŸ“… Published: Oct. 24, 2024, 4:31 p.m. πŸ”„ Last Modified: Nov. 7, 2024, 6:50 p.m.

6.9

CVSS4.0

CVE-2024-10335 - SourceCodester Garbage Collection Management System login.php sql injection

A vulnerability was found in SourceCodester Garbage Collection Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The…

πŸ“… Published: Oct. 24, 2024, 4:31 p.m. πŸ”„ Last Modified: Nov. 7, 2024, 6:52 p.m.

6.9

CVSS4.0

CVE-2024-9692 - Improper Access Control in Input in VIMESA VHF/FM Transmitter Blue Plus

VIMESA VHF/FM Transmitter Blue Plus is suffering from a Denial-of-Service (DoS) vulnerability. An unauthenticated attacker can issue an unauthorized HTTP GET request to the unprotected endpoint 'doreboot' and restart the transmitter operations.

πŸ“… Published: Oct. 24, 2024, 4:20 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2024-10347 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: Oct. 24, 2024, 3:01 p.m. πŸ”„ Last Modified: Feb. 11, 2025, 2:15 a.m.

6.1

CVSS3.1

CVE-2024-45031 - Apache Syncope: Stored XSS in Console and Enduser

When editing objects in the Syncope Console, incomplete HTML tags could be used to bypass HTML sanitization. This made it possible to inject stored XSS payloads which would trigger for other users during ordinary usage of the application. XSS payloads could also be injected in Syncope Enduser when …

πŸ“… Published: Oct. 24, 2024, 2:21 p.m. πŸ”„ Last Modified: Sept. 29, 2025, 9:48 p.m.

6.5

CVSS3.1

CVE-2024-49693 - WordPress Mega Elements – Addons for Elementor plugin <= 1.2.6 - Cross Site Scripting (XSS) vulnera…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kraft Plugins Mega Elements mega-elements-addons-for-elementor allows Stored XSS.This issue affects Mega Elements: from n/a through <= 1.2.6.

πŸ“… Published: Oct. 24, 2024, 12:41 p.m. πŸ”„ Last Modified: April 23, 2026, 3:19 p.m.

6.5

CVSS3.1

CVE-2024-49695 - WordPress WP Flow Plus plugin <= 5.2.3 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins WP Flow Plus wp-imageflow2 allows Stored XSS.This issue affects WP Flow Plus: from n/a through <= 5.2.3.

πŸ“… Published: Oct. 24, 2024, 12:38 p.m. πŸ”„ Last Modified: April 23, 2026, 3:19 p.m.

6.4

CVSS3.1

CVE-2024-10180 - Contact Form 7 - Repeatable Fields <= 2.0.1 - Authenticated (Contributor+) Stored Cross-Site Script…

The Contact Form 7 – Repeatable Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's field_group shortcode in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible …

πŸ“… Published: Oct. 24, 2024, 12:32 p.m. πŸ”„ Last Modified: April 8, 2026, 4:34 p.m.

5.9

CVSS3.1

CVE-2024-49696 - WordPress Photo Gallery, Images, Slider in Rbs Image Gallery plugin <= 3.2.21 - Cross Site Scriptin…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robosoft Robo Gallery robo-gallery allows Stored XSS.This issue affects Robo Gallery: from n/a through <= 3.2.21.

πŸ“… Published: Oct. 24, 2024, 12:29 p.m. πŸ”„ Last Modified: April 23, 2026, 3:19 p.m.

6.5

CVSS3.1

CVE-2024-49702 - WordPress myCred Elementor plugin <= 1.2.6 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal myCred Elementor mycred-for-elementor allows Stored XSS.This issue affects myCred Elementor: from n/a through <= 1.2.6.

πŸ“… Published: Oct. 24, 2024, 12:28 p.m. πŸ”„ Last Modified: April 23, 2026, 3:19 p.m.
Total resulsts: 349182
Page 8155 of 34,919
Β« previous page Β» next page
Filters