7.1

CVSS4.0

CVE-2024-47654 - No Rate Limiting vulnerability

This vulnerability exists in Shilpi Client Dashboard due to lack of rate limiting and Captcha protection for OTP requests in certain API endpoint. An unauthenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoints, which could lead t…

πŸ“… Published: Oct. 4, 2024, 12:18 p.m. πŸ”„ Last Modified: Oct. 16, 2024, 3:17 p.m.

7.1

CVSS4.0

CVE-2024-47653 - Missing Authorization Vulnerability

This vulnerability exists in Shilpi Client Dashboard due to lack of authorization for modification and cancellation requests through certain API endpoints. An authenticated remote attacker could exploit this vulnerability by placing or cancelling requests through API request body leading to unautho…

πŸ“… Published: Oct. 4, 2024, 12:15 p.m. πŸ”„ Last Modified: Oct. 16, 2024, 3:13 p.m.

5.1

CVSS3.1

CVE-2024-9481 - Out of Bounds write on scan of malformed eml file may crash the application

An out-of-bounds write in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed eml file to crash the application during file processing.

πŸ“… Published: Oct. 4, 2024, 12:15 p.m. πŸ”„ Last Modified: Nov. 8, 2024, 8:49 p.m.

7.6

CVSS4.0

CVE-2024-47652 - Insecure Authentication Vulnerability

This vulnerability exists in Shilpi Client Dashboard due to implementation of inadequate authentication mechanism in the login module wherein access to any users account is granted with just their corresponding mobile number. A remote attacker could exploit this vulnerability by providing mobile nu…

πŸ“… Published: Oct. 4, 2024, 12:13 p.m. πŸ”„ Last Modified: Oct. 16, 2024, 2:12 p.m.

7.1

CVSS4.0

CVE-2024-47651 - Parameter Pollution Vulnerability

This vulnerability exists in Shilpi Client Dashboard due to improper handling of multiple parameters in the API endpoint. An authenticated remote attacker could exploit this vulnerability by including multiple β€œuserid” parameters in the API request body leading to unauthorized access of sensitive i…

πŸ“… Published: Oct. 4, 2024, 12:07 p.m. πŸ”„ Last Modified: Oct. 10, 2024, 9:01 p.m.

8.2

CVSS4.0

CVE-2024-6400 - Cleartext Storage of Username and Password in Finrota's Netahsilat

Cleartext Storage of Sensitive Information, Exposure of Sensitive Information Through Data Queries vulnerability in Finrota Netahsilat allows Retrieve Embedded Sensitive Data, Authentication Bypass, IMAP/SMTP Command Injection, Collect Data from Common Resource Locations. This issue solved in versi…

πŸ“… Published: Oct. 4, 2024, 11:12 a.m. πŸ”„ Last Modified: Oct. 14, 2025, 1:15 p.m.

6.4

CVSS3.1

CVE-2024-9271 - Re:WP <= 1.0.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

The Re:WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject …

πŸ“… Published: Oct. 4, 2024, 9:30 a.m. πŸ”„ Last Modified: April 8, 2026, 5:13 p.m.

6.4

CVSS3.1

CVE-2024-9071 - Easy Demo Importer – A Modern One-Click Demo Import Solution <= 1.1.2 - Authenticated (Author+) Sto…

The Easy Demo Importer – A Modern One-Click Demo Import Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated at…

πŸ“… Published: Oct. 4, 2024, 9:30 a.m. πŸ”„ Last Modified: April 8, 2026, 4:42 p.m.

6.1

CVSS3.1

CVE-2024-9435 - ShiftController Employee Shift Scheduling <= 4.9.66 - Reflected Cross-Site Scripting

The ShiftController Employee Shift Scheduling plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL keys in all versions up to, and including, 4.9.66 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arb…

πŸ“… Published: Oct. 4, 2024, 6:48 a.m. πŸ”„ Last Modified: April 8, 2026, 5:27 p.m.

4.4

CVSS3.1

CVE-2024-9306 - WP Booking Calendar <= 10.6 - Authenticated (Admin+) Stored Cross-Site Scripting

The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 10.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permission…

πŸ“… Published: Oct. 4, 2024, 6:48 a.m. πŸ”„ Last Modified: April 8, 2026, 4:36 p.m.
Total resulsts: 349182
Page 8403 of 34,919
Β« previous page Β» next page
Filters