6.9

CVSS4.0

CVE-2024-6371 - itsourcecode Pool of Bethesda Online Reservation System controller.php sql injection

A vulnerability, which was classified as critical, has been found in itsourcecode Pool of Bethesda Online Reservation System 1.0. Affected by this issue is some unknown functionality of the file controller.php. The manipulation of the argument rmtype_id leads to sql injection. The attack may be lau…

πŸ“… Published: June 27, 2024, 12:31 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:49 a.m.

5.3

CVSS4.0

CVE-2024-6370 - LabVantage LIMS POST Request cross site scripting

A vulnerability classified as problematic was found in LabVantage LIMS 2017. Affected by this vulnerability is an unknown functionality of the file /labvantage/rc?command=file&file=WEB-OPAL/pagetypes/bulletins/sendbulletin.jsp of the component POST Request Handler. The manipulation of the argument …

πŸ“… Published: June 27, 2024, noon πŸ”„ Last Modified: Nov. 21, 2024, 9:49 a.m.

5.3

CVSS4.0

CVE-2024-6369 - LabVantage LIMS POST Request cross site scripting

A vulnerability classified as problematic has been found in LabVantage LIMS 2017. Affected is an unknown function of the file /labvantage/rc?command=page&sdcid=LV_ReagentLot of the component POST Request Handler. The manipulation of the argument mode leads to cross site scripting. It is possible to…

πŸ“… Published: June 27, 2024, noon πŸ”„ Last Modified: Nov. 21, 2024, 9:49 a.m.

5.3

CVSS4.0

CVE-2024-6368 - LabVantage LIMS POST Request cross site scripting

A vulnerability was found in LabVantage LIMS 2017. It has been rated as problematic. This issue affects some unknown processing of the file /labvantage/rc?command=page of the component POST Request Handler. The manipulation of the argument param1 leads to cross site scripting. The attack may be ini…

πŸ“… Published: June 27, 2024, 11:31 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:49 a.m.

5.3

CVSS4.0

CVE-2024-6367 - LabVantage LIMS POST Request cross site scripting

A vulnerability was found in LabVantage LIMS 2017. It has been declared as problematic. This vulnerability affects unknown code of the file /labvantage/rc?command=file&file=WEB-CORE/elements/files/filesembedded.jsp of the component POST Request Handler. The manipulation of the argument sdcid/keyid1…

πŸ“… Published: June 27, 2024, 11:31 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:49 a.m.

6.4

CVSS3.1

CVE-2024-6262 - Portfolio Gallery – Image Gallery Plugin <= 1.6.4 - Authenticated (Contributor+) DOM-Based Stored C…

The Portfolio Gallery – Image Gallery Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'PFG' shortcode in all versions up to, and including, 1.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible …

πŸ“… Published: June 27, 2024, 11:03 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-0949 - Improper Access Control in Talya Informatics' Elektraweb

Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability in Talya Informatics Elektraweb allows Authentication Bypass.This issue affects Elektraweb: before v17.0.68.

πŸ“… Published: June 27, 2024, 9:36 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2023-7270 - Local Privilege Escalation via MSI installer

An issue was discovered in SoftMaker Office 2024 / NX before revision 1214 and SoftMaker FreeOffice 2014 before revision 1215. FreeOffice 2021 is also affected, but won't be fixed. The SoftMaker Office and FreeOffice MSI installer files were found to produce a visible conhost.exe window runni…

πŸ“… Published: June 27, 2024, 9:28 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-0947 - Cookies Manipulation in Talya Informatics' Elektraweb

Reliance on Cookies without Validation and Integrity Checking vulnerability in Talya Informatics Elektraweb allows Session Credential Falsification through Manipulation, Accessing/Intercepting/Modifying HTTP Cookies, Manipulating Opaque Client-based Data Tokens.This issue affects Elektraweb: before…

πŸ“… Published: June 27, 2024, 9:27 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-4983 - The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <…

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜video_color’ parameter in all versions up to, and including, 5.6.0 due to insufficient input sanitization and output escap…

πŸ“… Published: June 27, 2024, 8:34 a.m. πŸ”„ Last Modified: April 8, 2026, 7:21 p.m.
Total resulsts: 349182
Page 9317 of 34,919
Β« previous page Β» next page
Filters