6.4

CVSS3.1

CVE-2024-5036 - Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Element…

The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜url’ parameter in all versions up to, and including, 3.5.4 due to insufficient input sa…

πŸ“… Published: June 20, 2024, 11:06 a.m. πŸ”„ Last Modified: April 8, 2026, 6:21 p.m.

5.3

CVSS4.0

CVE-2024-6182 - LabVantage LIMS cross site scripting

A vulnerability was found in LabVantage LIMS 2017. It has been rated as problematic. This issue affects some unknown processing of the file /labvantage/rc?command=page&page=LV_ViewSampleSpec&oosonly=Y&_sdialog=Y. The manipulation of the argument sdcid/keyid1 leads to cross site scripting. The attac…

πŸ“… Published: June 20, 2024, 11 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:49 a.m.

5.3

CVSS4.0

CVE-2024-6181 - LabVantage LIMS cross site scripting

A vulnerability was found in LabVantage LIMS 2017. It has been declared as problematic. This vulnerability affects unknown code of the file /labvantage/rc?command=file&file=WEB-CORE/elements/files/filesembedded.jsp&size=32. The manipulation of the argument height/width leads to cross site scripting…

πŸ“… Published: June 20, 2024, 11 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:49 a.m.

7.4

CVSS3.1

CVE-2024-28147 - Unrestricted Upload of Files in edu-sharing

An authenticated user can upload arbitrary files in the upload function for collection preview images. An attacker may upload an HTML file that includes malicious JavaScript code which will be executed if a user visits the direct URL of the collection preview image (Stored Cross Site Scripting)…

πŸ“… Published: June 20, 2024, 10:46 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS3.1

CVE-2024-34693 - Apache Superset: Server arbitrary file read

Improper Input Validation vulnerability in Apache Superset, allows for an authenticated attacker to create a MariaDB connection with local_infile enabled. If both the MariaDB server (off by default) and the local mysql client on the web server are set to allow for local infile, it's possible for th…

πŸ“… Published: June 20, 2024, 8:51 a.m. πŸ”„ Last Modified: Feb. 21, 2025, 4:55 p.m.

5.3

CVSS3.1

CVE-2024-29013 -

Heap-based buffer overflow vulnerability in the SonicOS SSL-VPN allows an authenticated remote attacker to cause Denial of Service (DoS) via memcpy function.

πŸ“… Published: June 20, 2024, 8:14 a.m. πŸ”„ Last Modified: March 25, 2025, 5:15 p.m.

4.9

CVSS3.1

CVE-2024-29012 -

Stack-based buffer overflow vulnerability in the SonicOS HTTP server allows an authenticated remote attacker to cause Denial of Service (DoS) via sscanf function.

πŸ“… Published: June 20, 2024, 8:11 a.m. πŸ”„ Last Modified: March 25, 2025, 5:15 p.m.

9.8

CVSS3.1

CVE-2024-4098 - Shariff Wrapper <= 4.6.13 - Unauthenticated Local File Inclusion

The Shariff Wrapper plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.6.13 via the shariff3uu_fetch_sharecounts function. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code i…

πŸ“… Published: June 20, 2024, 6:58 a.m. πŸ”„ Last Modified: April 8, 2026, 7:21 p.m.

7.1

CVSS3.1

CVE-2023-25646 - Permission and Access Control Vulnerability in ZTE H388X

There is an unauthorized access vulnerability in ZTE H388X. If H388X is caused by brute-force serial port cracking,attackers with common user permissions can use this vulnerability to obtain elevated permissions on the affected device by performing specific operations.

πŸ“… Published: June 20, 2024, 6:20 a.m. πŸ”„ Last Modified: Jan. 28, 2025, 4:29 p.m.

6.5

CVSS3.1

CVE-2024-5522 - HTML5 Video Player < 2.5.27 - Unauthenticated SQLi

The HTML5 Video Player WordPress plugin before 2.5.27 does not sanitize and escape a parameter from a REST route before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks

πŸ“… Published: June 20, 2024, 6 a.m. πŸ”„ Last Modified: May 19, 2025, 9:03 p.m.
Total resulsts: 349182
Page 9377 of 34,919
Β« previous page Β» next page
Filters