5.4

CVSS3.1

CVE-2024-9021 - Relevanssi < 4.23.1 - Contributor+ Stored XSS

In the process of testing the Relevanssi WordPress plugin before 4.23.1, a vulnerability was found that allows you to implement Stored XSS on behalf of the Contributor+ by embedding malicious script, which entails account takeover backdoor

📅 Published: Oct. 8, 2024, 6 a.m. 🔄 Last Modified: June 9, 2025, 9:30 p.m.

4.8

CVSS3.1

CVE-2024-8983 - Custom Twitter Feeds < 2.2.3 - Admin+ Stored XSS

Custom Twitter Feeds WordPress plugin before 2.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

📅 Published: Oct. 8, 2024, 6 a.m. 🔄 Last Modified: Sept. 30, 2025, 6:16 p.m.

6.4

CVSS3.1

CVE-2024-9292 - Bridge Core <= 3.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Bridge Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'formforall' shortcode in versions up to, and including, 3.2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contri…

📅 Published: Oct. 8, 2024, 5:36 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-21533 -

All versions of the package ggit are vulnerable to Arbitrary Argument Injection via the clone() API, which allows specifying the remote URL to clone and the file on disk to clone to. The library does not sanitize for user input or validate a given URL scheme, nor does it properly pass command-line …

📅 Published: Oct. 8, 2024, 5 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS3.1

CVE-2024-21532 -

All versions of the package ggit are vulnerable to Command Injection via the fetchTags(branch) API, which allows user input to specify the branch to be fetched and then concatenates this string along with a git command which is then passed to the unsafe exec() Node.js child process API.

📅 Published: Oct. 8, 2024, 5 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

3.3

CVSS3.1

CVE-2024-9026 - PHP-FPM logs from children may be altered

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using PHP-FPM SAPI and it is configured to catch workers output through catch_workers_output = yes, it may be possible to pollute the final log or remove up to 4 characters from the log messages by manipulating log …

📅 Published: Oct. 8, 2024, 4:07 a.m. 🔄 Last Modified: Nov. 3, 2025, 11:17 p.m.

5.4

CVSS3.1

CVE-2024-47594 - Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal (KMC)

SAP NetWeaver Enterprise Portal (KMC) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability in KMC servlet. An attacker could craft a script and trick the user into clicking it. When a victim who is registered on the portal clicks on such link, confide…

📅 Published: Oct. 8, 2024, 3:21 a.m. 🔄 Last Modified: Nov. 14, 2024, 4:12 p.m.

4.3

CVSS3.1

CVE-2024-45282 - HTTP Verb Tampering in SAP S/4 HANA(Manage Bank Statements)

Fields which are in 'read only' state in Bank Statement Draft in Manage Bank Statements application, could be modified by MERGE method. The property of an OData entity representing assumably immutable method is not protected against external modifications leading to integrity violations. Confidenti…

📅 Published: Oct. 8, 2024, 3:21 a.m. 🔄 Last Modified: Nov. 14, 2024, 5:56 p.m.

5.4

CVSS3.1

CVE-2024-45278 - Cross-Site Scripting (XSS) vulnerability in SAP Commerce Backoffice

SAP Commerce Backoffice does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can cause limited impact on confidentiality and integrity of the application.

📅 Published: Oct. 8, 2024, 3:21 a.m. 🔄 Last Modified: Nov. 14, 2024, 5:17 p.m.

4.3

CVSS3.1

CVE-2024-45277 - Prototype Pollution vulnerability in SAP HANA Client

The SAP HANA Node.js client package versions from 2.0.0 before 2.21.31 is impacted by Prototype Pollution vulnerability allowing an attacker to add arbitrary properties to global object prototypes. This is due to improper user input sanitation when using the nestTables feature causing low impact on…

📅 Published: Oct. 8, 2024, 3:21 a.m. 🔄 Last Modified: Nov. 14, 2024, 5:54 p.m.
Total resulsts: 349182
Page 8368 of 34,919
« previous page » next page
Filters