5.3

CVSS4.0

CVE-2024-6369 - LabVantage LIMS POST Request cross site scripting

A vulnerability classified as problematic has been found in LabVantage LIMS 2017. Affected is an unknown function of the file /labvantage/rc?command=page&sdcid=LV_ReagentLot of the component POST Request Handler. The manipulation of the argument mode leads to cross site scripting. It is possible toโ€ฆ

๐Ÿ“… Published: June 27, 2024, noon ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:49 a.m.

5.3

CVSS4.0

CVE-2024-6368 - LabVantage LIMS POST Request cross site scripting

A vulnerability was found in LabVantage LIMS 2017. It has been rated as problematic. This issue affects some unknown processing of the file /labvantage/rc?command=page of the component POST Request Handler. The manipulation of the argument param1 leads to cross site scripting. The attack may be iniโ€ฆ

๐Ÿ“… Published: June 27, 2024, 11:31 a.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:49 a.m.

5.3

CVSS4.0

CVE-2024-6367 - LabVantage LIMS POST Request cross site scripting

A vulnerability was found in LabVantage LIMS 2017. It has been declared as problematic. This vulnerability affects unknown code of the file /labvantage/rc?command=file&file=WEB-CORE/elements/files/filesembedded.jsp of the component POST Request Handler. The manipulation of the argument sdcid/keyid1โ€ฆ

๐Ÿ“… Published: June 27, 2024, 11:31 a.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:49 a.m.

6.4

CVSS3.1

CVE-2024-6262 - Portfolio Gallery โ€“ Image Gallery Plugin <= 1.6.4 - Authenticated (Contributor+) DOM-Based Stored Cโ€ฆ

The Portfolio Gallery โ€“ Image Gallery Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'PFG' shortcode in all versions up to, and including, 1.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible โ€ฆ

๐Ÿ“… Published: June 27, 2024, 11:03 a.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:49 a.m.

9.8

CVSS3.1

CVE-2024-0949 - Improper Access Control in Talya Informatics' Elektraweb

Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability in Talya Informatics Elektraweb allows Authentication Bypass.This issue affects Elektraweb: before v17.0.68.

๐Ÿ“… Published: June 27, 2024, 9:36 a.m. ๐Ÿ”„ Last Modified: Oct. 14, 2025, 1:15 p.m.

5.3

CVSS3.1

CVE-2023-7270 - Local Privilege Escalation via MSI installer

An issue was discovered in SoftMaker Office 2024 / NX before revision 1214 and SoftMaker FreeOffice 2014 before revision 1215. FreeOffice 2021 is also affected, but won't be fixed. The SoftMaker Office and FreeOffice MSI installer files were found to produce a visible conhost.exe window runniโ€ฆ

๐Ÿ“… Published: June 27, 2024, 9:28 a.m. ๐Ÿ”„ Last Modified: Feb. 13, 2025, 5:27 p.m.

9.8

CVSS3.1

CVE-2024-0947 - Cookies Manipulation in Talya Informatics' Elektraweb

Reliance on Cookies without Validation and Integrity Checking vulnerability in Talya Informatics Elektraweb allows Session Credential Falsification through Manipulation, Accessing/Intercepting/Modifying HTTP Cookies, Manipulating Opaque Client-based Data Tokens.This issue affects Elektraweb: beforeโ€ฆ

๐Ÿ“… Published: June 27, 2024, 9:27 a.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 8:47 a.m.

6.4

CVSS3.1

CVE-2024-4983 - The Plus Addons for Elementor โ€“ Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <โ€ฆ

The The Plus Addons for Elementor โ€“ Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the โ€˜video_colorโ€™ parameter in all versions up to, and including, 5.6.0 due to insufficient input sanitization and output escapโ€ฆ

๐Ÿ“… Published: June 27, 2024, 8:34 a.m. ๐Ÿ”„ Last Modified: Jan. 29, 2025, 6:07 p.m.

6.4

CVSS3.1

CVE-2024-5601 - Create by Mediavine <= 1.9.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Schema โ€ฆ

The Create by Mediavine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Schema Meta shortcode in all versions up to, and including, 1.9.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticatโ€ฆ

๐Ÿ“… Published: June 27, 2024, 7:44 a.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:47 a.m.

7.7

CVSS3.1

CVE-2024-22232 - Specially crafted url can be created which leads to a directory traversal in the salt file server

A specially crafted url can be created which leads to a directory traversal in the salt file server. A malicious user can read an arbitrary file from a Salt masterโ€™s filesystem.

๐Ÿ“… Published: June 27, 2024, 6:54 a.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 8:55 a.m.
Total resulsts: 342650
Page 8664 of 34,265
ยซ previous page ยป next page
Filters