5.3
CVE-2024-6369 - LabVantage LIMS POST Request cross site scripting
A vulnerability classified as problematic has been found in LabVantage LIMS 2017. Affected is an unknown function of the file /labvantage/rc?command=page&sdcid=LV_ReagentLot of the component POST Request Handler. The manipulation of the argument mode leads to cross site scripting. It is possible toโฆ
5.3
CVE-2024-6368 - LabVantage LIMS POST Request cross site scripting
A vulnerability was found in LabVantage LIMS 2017. It has been rated as problematic. This issue affects some unknown processing of the file /labvantage/rc?command=page of the component POST Request Handler. The manipulation of the argument param1 leads to cross site scripting. The attack may be iniโฆ
5.3
CVE-2024-6367 - LabVantage LIMS POST Request cross site scripting
A vulnerability was found in LabVantage LIMS 2017. It has been declared as problematic. This vulnerability affects unknown code of the file /labvantage/rc?command=file&file=WEB-CORE/elements/files/filesembedded.jsp of the component POST Request Handler. The manipulation of the argument sdcid/keyid1โฆ
6.4
CVE-2024-6262 - Portfolio Gallery โ Image Gallery Plugin <= 1.6.4 - Authenticated (Contributor+) DOM-Based Stored Cโฆ
The Portfolio Gallery โ Image Gallery Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'PFG' shortcode in all versions up to, and including, 1.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible โฆ
9.8
CVE-2024-0949 - Improper Access Control in Talya Informatics' Elektraweb
Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability in Talya Informatics Elektraweb allows Authentication Bypass.This issue affects Elektraweb: before v17.0.68.
5.3
CVE-2023-7270 - Local Privilege Escalation via MSI installer
An issue was discovered in SoftMaker Office 2024 / NX before revision 1214 and SoftMaker FreeOffice 2014 before revision 1215. FreeOffice 2021 is also affected, but won't be fixed. The SoftMaker Office and FreeOffice MSI installer files were found to produce a visible conhost.exe window runniโฆ
9.8
CVE-2024-0947 - Cookies Manipulation in Talya Informatics' Elektraweb
Reliance on Cookies without Validation and Integrity Checking vulnerability in Talya Informatics Elektraweb allows Session Credential Falsification through Manipulation, Accessing/Intercepting/Modifying HTTP Cookies, Manipulating Opaque Client-based Data Tokens.This issue affects Elektraweb: beforeโฆ
6.4
CVE-2024-4983 - The Plus Addons for Elementor โ Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <โฆ
The The Plus Addons for Elementor โ Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the โvideo_colorโ parameter in all versions up to, and including, 5.6.0 due to insufficient input sanitization and output escapโฆ
6.4
CVE-2024-5601 - Create by Mediavine <= 1.9.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Schema โฆ
The Create by Mediavine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Schema Meta shortcode in all versions up to, and including, 1.9.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticatโฆ
7.7
CVE-2024-22232 - Specially crafted url can be created which leads to a directory traversal in the salt file server
A specially crafted url can be created which leads to a directory traversal in the salt file server. A malicious user can read an arbitrary file from a Salt masterโs filesystem.