ID | Summary | Flags | Max Score |
---|---|---|---|
CVE-2024-51000 | Netgear R8500 v1.0.2.160 was discovered to contain multiple stack overflow vulnerabilities in the co... | | |
CVE-2024-51001 | Netgear R8500 v1.0.2.160 was discovered to contain a stack overflow via the sysDNSHost parameter at ... | | |
CVE-2024-51002 | Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered... | | |
CVE-2024-51003 | Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered... | | |
CVE-2024-51004 | Netgear R8500 v1.0.2.160 and R7000P v1.3.3.154 were discovered to multiple stack overflow vulnerabil... | | |
CVE-2024-51005 | Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the share_na... | | |
CVE-2024-51006 | Netgear R8500 v1.0.2.160 was discovered to contain a stack overflow via the ipv6_static_ip parameter... | | |
CVE-2024-51007 | Netgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the passphrase parameter at w... | | |
CVE-2024-51008 | Netgear XR300 v1.0.3.78 was discovered to contain a command injection vulnerability in the system_na... | | |
CVE-2024-51009 | Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gate... | | |
CVE-2024-51010 | Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered... | | |
CVE-2024-51011 | Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack... | | |
CVE-2024-51012 | Netgear R8500 v1.0.2.160 was discovered to contain a stack overflow via the ipv6_pri_dns parameter a... | | |
CVE-2024-51013 | Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the RADIUSAddr%d_wla parame... | | |
CVE-2024-51014 | Netgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the ssid_an parameter in brid... | | |
CVE-2024-51015 | Netgear R7000P v1.3.3.154 was discovered to contain a command injection vulnerability via the device... | | |
CVE-2024-51016 | Netgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the addName%d parameter in us... | | |
CVE-2024-51017 | Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the l2tp_user_netmask param... | | |
CVE-2024-51018 | Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the pptp_user_netmask param... | | |
CVE-2024-51019 | Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the pppoe_localnetmask para... | | |
CVE-2024-51020 | Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the apn parameter at usbISP... | | |
CVE-2024-51021 | Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a comma... | | |
CVE-2024-51022 | Netgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the ssid parameter in bridge_... | | |
CVE-2024-51023 | D-Link DIR_823G 1.0.2B05 was discovered to contain a command injection vulnerability via the Address... | | |
CVE-2024-51024 | D-Link DIR_823G 1.0.2B05 was discovered to contain a command injection vulnerability via the HostNam... | | |
CVE-2024-51026 | The NetAdmin IAM system (version 4.0.30319) has a Cross Site Scripting (XSS) vulnerability in the /B... | | |
CVE-2024-51027 | Ruijie NBR800G gateway NBR_RGOS_11.1(6)B4P9 is vulnerable to command execution in /itbox_pi/networks... | | |
CVE-2024-51030 | A SQL injection vulnerability in manage_client.php and view_cab.php of Sourcecodester Cab Management... | | |
CVE-2024-51031 | A Cross-site Scripting (XSS) vulnerability in manage_account.php in Sourcecodester Cab Management Sy... | | |
CVE-2024-51032 | A Cross-site Scripting (XSS) vulnerability in manage_recipient.php of Sourcecodester Toll Tax Manage... | | |
CVE-2024-51037 | An issue in kodbox v.1.52.04 and before allows a remote attacker to obtain sensitive information via... | | |
CVE-2024-51051 | AVSCMS v8.2.0 was discovered to contain weak default credentials for the Administrator account.... | | |
CVE-2024-51053 | An arbitrary file upload vulnerability in the component /main/fileupload.php of AVSCMS v8.2.0 allows... | | |
CVE-2024-51054 | A Cross Site Scriptng (XSS) vulnerability was found in /omrs/admin/search.php in PHPGurukul Online M... | E | |
CVE-2024-51055 | An issue Hoosk v1.7.1 allows a remote attacker to execute arbitrary code via a crafted script to the... | E | |
CVE-2024-51058 | Local File Inclusion (LFI) vulnerability has been discovered in TCPDF 6.7.5. This vulnerability enab... | | |
CVE-2024-51060 | Projectworlds Online Admission System v1 is vulnerable to SQL Injection in index.php via the 'a_id' ... | E | |
CVE-2024-51063 | Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection in add-teacher.php ... | E | |
CVE-2024-51064 | Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection via the tid paramet... | E | |
CVE-2024-51065 | Phpgurukul Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in admin/index.php v... | E | |
CVE-2024-51066 | An Insecure Direct Object Reference (IDOR) vulnerability in appointment-detail.php in Phpgurukul's B... | E | |
CVE-2024-51072 | An issue in KIA Seltos vehicle instrument cluster with software and hardware v1.0 allows attackers t... | | |
CVE-2024-51073 | An issue in KIA Seltos vehicle instrument cluster with software and hardware v1.0 allows attackers t... | | |
CVE-2024-51074 | Incorrect access control in KIA Seltos vehicle instrument cluster with software and hardware v1.0 al... | | |
CVE-2024-51075 | A Reflected Cross Site Scripting (XSS) vulnerability was found in /odms/admin/user-search.php in PHP... | E | |
CVE-2024-51076 | A Reflected Cross Site Scripting (XSS) vulnerability was found in /odms/admin/booking-search.php in ... | E | |
CVE-2024-51091 | Cross Site Scripting vulnerability in seajs v.2.2.3 allows a remote attacker to execute arbitrary co... | E | |
CVE-2024-51093 | Stored Cross-Site Scripting (XSS) vulnerability in Snipe-IT - v7.0.13 allows an attacker to upload a... | | |
CVE-2024-51094 | An issue in Snipe-IT v.7.0.13 build 15514 allows a low-privileged attacker to modify their profile n... | | |
CVE-2024-51099 | A reflected cross-site scripting (XSS) vulnerability in the component mcgs/download-medical-cards.ph... | | |
CVE-2024-51101 | PHPGURUKUL Restaurant Table Booking System using PHP and MySQL v1.0 was discovered to contain a SQL ... | E | |
CVE-2024-51102 | PHPGURUKUL Student Management System using PHP and MySQL v1 was discovered to contain multiple SQL i... | | |
CVE-2024-51103 | PHPGURUKUL Student Management System using PHP and MySQL v1 was discovered to contain multiple SQL i... | | |
CVE-2024-51106 | A cross-site scripting (XSS) vulnerability in the component mcgs/admin/aboutus.php of PHPGURUKUL Med... | E | |
CVE-2024-51107 | Multiple stored cross-site scripting (XSS) vulnerabilities in the component /mcgs/admin/contactus.ph... | E | |
CVE-2024-51108 | Multiple stored cross-site scripting (XSS) vulnerabilities in the component /admin/card-bwdates-repo... | E | |
CVE-2024-51111 | Cross-Site Scripting (XSS) vulnerability in Pnetlab 5.3.11 allows an attacker to inject malicious sc... | | |
CVE-2024-51112 | Open Redirect vulnerability in Pnetlab 5.3.11 allows an attacker to manipulate URLs to redirect user... | | |
CVE-2024-51114 | An issue in Beijing Digital China Yunke Information Technology Co.Ltd v.7.2.6.120 allows a remote at... | | |
CVE-2024-51115 | DCME-320 v7.4.12.90 was discovered to contain a command injection vulnerability.... | | |
CVE-2024-51116 | Tenda AC6 v2.0 V15.03.06.50 was discovered to contain a buffer overflow in the function 'formSetPPTP... | E | |
CVE-2024-51122 | Cross Site Scripting vulnerability in Zertificon Z1 SecureMail Z1 CertServer v.3.16.4-2516-debian12 ... | | |
CVE-2024-51123 | An issue in Zertificon Z1 SecureMail Z1 SecureMail Gateway 4.44.2-7240-debian12 allows a remote atta... | | |
CVE-2024-51127 | An issue in the createTempFile method of hornetq v2.4.9 allows attackers to arbitrarily overwrite fi... | E M | |
CVE-2024-51132 | An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sen... | | |
CVE-2024-51135 | An XML External Entity (XXE) vulnerability in the component DocumentBuilderFactory of powertac-serve... | | |
CVE-2024-51136 | An XML External Entity (XXE) vulnerability in Dmoz2CSV in openimaj v1.3.10 allows attackers to acces... | E | |
CVE-2024-51138 | Vigor165/166 4.2.7 and earlier; Vigor2620/LTE200 3.9.8.9 and earlier; Vigor2860/2925 3.9.8 and earli... | | |
CVE-2024-51139 | Buffer Overflow vulnerability in Vigor2620/LTE200 3.9.8.9 and earlier and Vigor2860/2925 3.9.8 and e... | | |
CVE-2024-51141 | An issue in TOTOLINK Bluetooth Wireless Adapter A600UB allows a local attacker to execute arbitrary ... | | |
CVE-2024-51142 | Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows an attacker to execute arbitrary ... | E | |
CVE-2024-51144 | Cross Site Request Forgery (CSRF) vulnerability exists in the 'pvmsg.php?action=add_message', pvmsg.... | | |
CVE-2024-51151 | D-Link DI-8200 16.07.26A1 is vulnerable to remote command execution in the msp_info_htm function via... | E | |
CVE-2024-51152 | File Upload vulnerability in Laravel CMS v.1.4.7 and before allows a remote attacker to execute arbi... | E | |
CVE-2024-51156 | 07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component 'erp... | E | |
CVE-2024-51157 | 07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component http... | E | |
CVE-2024-51162 | An issue in Audimex EE versions 15.1.20 and earlier allowing a remote attacker to escalate privilege... | | |
CVE-2024-51163 | A Local File Inclusion vulnerability in Vegam Solutions Vegam 4i versions 6.3.47.0 and earlier allow... | | |
CVE-2024-51164 | Multiple parameters have SQL injection vulnerability in JEPaaS 7.2.8 via /je/login/btnLog/insertBtnL... | | |
CVE-2024-51165 | SQL injection vulnerability in JEPAAS7.2.8, via /je/rbac/rbac/loadLoginCount in the dateVal paramete... | | |
CVE-2024-51175 | An issue in H3C switch h3c-S1526 allows a remote attacker to obtain sensitive information via the S1... | | |
CVE-2024-51179 | An issue in Open 5GS v.2.7.1 allows a remote attacker to cause a denial of service via the Network F... | | |
CVE-2024-51180 | A Reflected Cross Site Scripting (XSS) vulnerability was found in /ifscfinder/index.php in PHPGuruku... | E M | |
CVE-2024-51181 | A Reflected Cross Site Scripting (XSS) vulnerability was found in /ifscfinder/admin/profile.php in P... | E M | |
CVE-2024-51182 | HTML Injection vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to inj... | E | |
CVE-2024-51186 | D-Link DIR-820L 1.05b03 was discovered to contain a remote code execution (RCE) vulnerability via th... | E | |
CVE-2024-51187 | TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-... | E | |
CVE-2024-51188 | TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-... | E | |
CVE-2024-51189 | TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-... | E | |
CVE-2024-51190 | TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-... | E | |
CVE-2024-51208 | File Upload vulnerability in change-image.php in Anuj Kumar's Boat Booking System version 1.0 allows... | | |
CVE-2024-51209 | Cross-Site Scripting (XSS) vulnerabilities in Anuj Kumar's Client Management System Version 1.2 allo... | E | |
CVE-2024-51210 | Firepad through 1.5.11 allows remote attackers, who have knowledge of a pad ID, to retrieve both the... | | |
CVE-2024-51211 | SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetus... | | |
CVE-2024-51213 | Cross Site Scripting vulnerability in Online Shop Store v.1.0 allows a remote attacker to execute ar... | | |
CVE-2024-51228 | An issue in TOTOLINK-CX-A3002RU V1.0.4-B20171106.1512 and TOTOLINK-CX-N150RT V2.1.6-B20171121.1002 a... | | |
CVE-2024-51229 | Cross Site Scripting vulnerability in LinZhaoguan pb-cms v.2.0 allows a remote attacker to execute a... | | |
CVE-2024-51240 | An issue in the luci-mod-rpc package in OpenWRT Luci LTS allows for privilege escalation from an adm... | | |
CVE-2024-51242 | A Server-Side Request Forgery (SSRF) vulnerability has been identified in eladmin 2.7 and earlier in... | E | |
CVE-2024-51243 | The eladmin v2.7 and before contains a remote code execution (RCE) vulnerability that can control al... | E | |
CVE-2024-51244 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and exec... | E | |
CVE-2024-51245 | In DrayTek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and exec... | E | |
CVE-2024-51246 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and exec... | | |
CVE-2024-51247 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and exec... | E | |
CVE-2024-51248 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and exec... | E | |
CVE-2024-51249 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and exec... | | |
CVE-2024-51251 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and exec... | | |
CVE-2024-51252 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and exec... | E | |
CVE-2024-51253 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and exec... | | |
CVE-2024-51254 | DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and ex... | | |
CVE-2024-51255 | DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and ex... | | |
CVE-2024-51257 | DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and ex... | | |
CVE-2024-51258 | DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and ex... | | |
CVE-2024-51259 | DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and ex... | | |
CVE-2024-51260 | DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and ex... | | |
CVE-2024-51296 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and exec... | | |
CVE-2024-51298 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and exec... | | |
CVE-2024-51299 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and exec... | | |
CVE-2024-51300 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and exec... | | |
CVE-2024-51301 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and exec... | | |
CVE-2024-51304 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and exec... | | |
CVE-2024-51319 | A local file include vulnerability in the /servlet/Report of Zucchetti Ad Hoc Infinity 2.4 allows an... | E | |
CVE-2024-51320 | Cross Site Scripting vulnerability in Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker... | E | |
CVE-2024-51321 | In Zucchetti Ad Hoc Infinity 2.4, an improper check on the m_cURL parameter allows an attacker to re... | E | |
CVE-2024-51322 | Cross Site Scripting vulnerability in Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker... | E | |
CVE-2024-51324 | An issue in the BdApiUtil driver of Baidu Antivirus v5.2.3.116083 allows attackers to terminate arbi... | | |
CVE-2024-51326 | SQL Injection vulnerability in projectworlds Travel management System v.1.0 allows a remote attacker... | E | |
CVE-2024-51327 | SQL Injection in loginform.php in ProjectWorld's Travel Management System v1.0 allows remote attacke... | E | |
CVE-2024-51328 | Cross Site Scripting vulnerability in addcategory.php in projectworld's Travel Management System v1.... | E | |
CVE-2024-51329 | A Host header injection vulnerability in Agile-Board 1.0 allows attackers to obtain the password res... | E | |
CVE-2024-51330 | An issue in UltiMaker Cura v.4.41 and 5.8.1 and before allows a local attacker to execute arbitrary ... | | |
CVE-2024-51337 | Cross Site Scripting vulnerability in Gibbon before v.27.0.01 and fixed in v.28.0.00 allows a remote... | | |
CVE-2024-51358 | An issue in Linux Server Heimdall v.2.6.1 allows a remote attacker to execute arbitrary code via a c... | | |
CVE-2024-51360 | An issue in Hospital Management System In PHP V4.0 allows a remote attacker to execute arbitrary cod... | E | |
CVE-2024-51362 | The LSC Smart Connect Indoor IP Camera V7.6.32 is vulnerable to an information disclosure issue wher... | | |
CVE-2024-51363 | Insecure deserialization in Hodoku v2.3.0 to v2.3.2 allows attackers to execute arbitrary code.... | | |
CVE-2024-51364 | An arbitrary file upload vulnerability in ModbusMechanic v3.0 allows attackers to execute arbitrary ... | | |
CVE-2024-51365 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by ... | R | |
CVE-2024-51366 | An arbitrary file upload vulnerability in the component \Roaming\Omega of OmegaT v6.0.1 allows attac... | | |
CVE-2024-51367 | An arbitrary file upload vulnerability in the component \Users\username.BlackBoard of BlackBoard v2.... | | |
CVE-2024-51376 | Directory Traversal vulnerability in yeqifu carRental v.1.0 allows a remote attacker to obtain sensi... | | |
CVE-2024-51377 | An issue in Ladybird Web Solution Faveo Helpdesk & Servicedesk (On-Premise and Cloud) 9.2.0 allows a... | E | |
CVE-2024-51378 | getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allow... | KEV E S | |
CVE-2024-51379 | Stored Cross-Site Scripting (XSS) vulnerability discovered in JATOS v3.9.3. The vulnerability exists... | | |
CVE-2024-51380 | Stored Cross-Site Scripting (XSS) vulnerability discovered in the Properties Component of JATOS v3.9... | | |
CVE-2024-51381 | Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 that allows attackers to perform act... | | |
CVE-2024-51382 | Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 allows an attacker to reset the admi... | | |
CVE-2024-51398 | Altai Technologies Ltd Altai X500 Indoor 22 802.11ac Wave 2 AP web Management Weak password leakage ... | | |
CVE-2024-51399 | Altai Technologies Ltd Altai IX500 Indoor 22 802.11ac Wave 2 AP After login, there are file reads in... | | |
CVE-2024-51406 | Floodlight SDN Open Flow Controller v.1.2 has an issue that allows local hosts to build fake LLDP pa... | | |
CVE-2024-51407 | Floodlight SDN OpenFlow Controller v.1.2 has an issue that allows local hosts to construct false bro... | E | |
CVE-2024-51408 | AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to... | E | |
CVE-2024-51409 | Buffer Overflow vulnerability in Tenda O3 v.1.0.0.5 allows a remote attacker to cause a denial of se... | E | |
CVE-2024-51417 | An issue in System.Linq.Dynamic.Core before 1.6.0 allows remote access to properties on reflection t... | | |
CVE-2024-51419 | Cross Site Scripting vulnerability in Shenzhen Interconnection Harbor Network Technology Co., Ltd Of... | | |
CVE-2024-51424 | An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote ... | | |
CVE-2024-51425 | An issue in the WaterToken smart contract (which can be run on the Ethereum blockchain) allows remot... | | |
CVE-2024-51426 | An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote ... | | |
CVE-2024-51427 | An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote ... | | |
CVE-2024-51428 | An issue in Espressif Esp idf v5.3.0 allows attackers to cause a Denial of Service (DoS) via a craft... | | |
CVE-2024-51430 | Cross Site Scripting vulnerability in online diagnostic lab management system using php v.1.0 allows... | | |
CVE-2024-51431 | LB-LINK BL-WR 1300H v.1.0.4 contains hardcoded credentials stored in /etc/shadow which are easily gu... | E | |
CVE-2024-51432 | Cross Site Scripting vulnerability in FiberHome HG6544C RP2743 allows an attacker to execute arbitra... | | |
CVE-2024-51434 | Inconsistent | | |
CVE-2024-51440 | An issue in Nothing Tech Nothing OS v.2.6 allows a local attacker to escalate privileges via the NtB... | | |
CVE-2024-51442 | Command Injection in Minidlna version v1.3.3 and before allows an attacker to execute arbitrary OS c... | | |
CVE-2024-51444 | A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions <... | | |
CVE-2024-51445 | A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions <... | | |
CVE-2024-51446 | A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions <... | | |
CVE-2024-51447 | A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions <... | | |
CVE-2024-51448 | IBM Robotic Process Automation privilege escalation | | |
CVE-2024-51450 | IBM Security Verify Directory Command Execution | | |
CVE-2024-51453 | IBM Sterling Secure Proxy directory traversal | S | |
CVE-2024-51456 | IBM Robotic Process Automation information disclosure | | |
CVE-2024-51457 | IBM Robotic Process Automation for Cloud Pak cross-site scripting | | |
CVE-2024-51459 | IBM InfoSphere Server Information command execution | | |
CVE-2024-51460 | IBM InfoSphere Information Server information disclosure | | |
CVE-2024-51461 | IBM QRadar WinCollect Agent denial of service | | |
CVE-2024-51462 | IBM QRadar WinCollect Agent data manipulation | | |
CVE-2024-51463 | IBM i server-side request forgery | | |
CVE-2024-51464 | IBM i authentication bypass | | |
CVE-2024-51465 | IBM App Connect Enterprise Certified Container command execution | | |
CVE-2024-51466 | IBM Cognos Analytics expression language injection | | |
CVE-2024-51470 | IBM MQ denial of service | | |
CVE-2024-51471 | IBM MQ Appliance denial of service | | |
CVE-2024-51472 | IBM DevOps Deploy / IBM UrbanCode Deploy HTML injection | | |
CVE-2024-51475 | IBM Content Navigator HTML injection | S | |
CVE-2024-51476 | IBM Concert Software information disclosure | | |
CVE-2024-51477 | IBM InfoSphere Information Server information disclosure | | |
CVE-2024-51478 | Use of a Broken or Risky Cryptographic Algorithm in YesWiki | E S | |
CVE-2024-51479 | Authorization bypass in Next.js | | |
CVE-2024-51480 | RedisTimeSeries Integer Overflow Remote Code Execution Vulnerability | | |
CVE-2024-51481 | Nix allows macOS sandbox escape via built-in builders | | |
CVE-2024-51482 | Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64 | | |
CVE-2024-51483 | changedetection.io Path Traversal vulnerability | | |
CVE-2024-51484 | Insufficient Validation in Controllers (Activation/Deactivation) in Ampache | E | |
CVE-2024-51485 | Insufficient Validation in Plugins (Activation/Deactivation) in Ampache | E | |
CVE-2024-51486 | Stored Cross-Site Scripting in Ampache | E | |
CVE-2024-51487 | Insufficient Validation in Catalog (Activation/Deactivation) in Ampache | E | |
CVE-2024-51488 | Insufficient Validation in Delete Message in Ampache | E | |
CVE-2024-51489 | Insufficient Message Token Validation in Ampache | E | |
CVE-2024-51490 | Stored Cross-Site Scripting in Ampache | E | |
CVE-2024-51491 | Process crash during CRL-based revocation check on OS using separate mount point for temp Directory in notation-go | E | |
CVE-2024-51492 | Zusam vulnerable to stored XSS, allowing token theft via crafted SVG | | |
CVE-2024-51493 | API key access in settings without reauthentication in OctoPrint | | |
CVE-2024-51494 | LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/app/Http/Controllers/Table/EditPortsController.php | E S | |
CVE-2024-51495 | LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/dev-overview-data.inc.php | E S | |
CVE-2024-51496 | LibreNMS has a Reflected XSS ('Cross-site Scripting') in librenms/includes/html/pages/wireless.inc.php | E S | |
CVE-2024-51497 | LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/print-customoid.php | E S | |
CVE-2024-51498 | [@imput/cobalt-web] Cross-site Scripting when downloading picker image from malicious instance | | |
CVE-2024-51499 | MarkUs Arbitrary File Write leading up to remote code execution (student accounts) | | |
CVE-2024-51500 | Failure to check for packets from the broadcast address allows potential DDoS amplification attack in Meshtastic firmware | | |
CVE-2024-51501 | CRLF injection in Refit's [Header], [HeaderCollection] and [Authorize] attributes | | |
CVE-2024-51502 | Panic Vulnerability in loona-hpack | | |
CVE-2024-51503 | A security agent manual scan command injection vulnerability in the Trend Micro Deep Security 20 Age... | | |
CVE-2024-51504 | Apache ZooKeeper: Authentication bypass with IP-based authentication in Admin Server | | |
CVE-2024-51505 | An issue was discovered in Atos Eviden IDRA before 2.7.1. A highly trusted role (Config Admin) could... | | |
CVE-2024-51506 | Tiki through 27.0 allows users who have certain permissions to insert a "Create a Wiki Pages" stored... | | |
CVE-2024-51507 | Tiki through 27.0 allows users who have certain permissions to insert a "Create/Edit External Wiki" ... | | |
CVE-2024-51508 | Tiki through 27.0 allows users who have certain permissions to insert a "Create/Edit External Wiki" ... | | |
CVE-2024-51509 | Tiki through 27.0 allows users who have certain permissions to insert a "Modules" (aka tiki-admin_mo... | | |
CVE-2024-51510 | Out-of-bounds access vulnerability in the logo module Impact: Successful exploitation of this vulner... | | |
CVE-2024-51511 | Vulnerability of parameter type not being verified in the WantAgent module Impact: Successful exploi... | | |
CVE-2024-51512 | Vulnerability of parameter type not being verified in the WantAgent module Impact: Successful exploi... | | |
CVE-2024-51513 | Vulnerability of processes not being fully terminated in the VPN module Impact: Successful exploitat... | | |
CVE-2024-51514 | Vulnerability of pop-up windows belonging to no app in the VPN module Impact: Successful exploitati... | | |
CVE-2024-51515 | Race condition vulnerability in the kernel network module Impact:Successful exploitation of this vul... | | |
CVE-2024-51516 | Permission control vulnerability in the ability module Impact: Successful exploitation of this vulne... | | |
CVE-2024-51517 | Vulnerability of improper memory access in the phone service module Impact: Successful exploitation ... | | |
CVE-2024-51518 | Vulnerability of message types not being verified in the advanced messaging modul Impact: Successful... | | |
CVE-2024-51519 | Vulnerability of input parameters not being verified in the HDC module Impact: Successful exploitati... | | |
CVE-2024-51520 | Vulnerability of input parameters not being verified in the HDC module Impact: Successful exploitati... | | |
CVE-2024-51521 | Input parameter verification vulnerability in the background service module Impact: Successful explo... | | |
CVE-2024-51522 | Vulnerability of improper device information processing in the device management module Impact: Succ... | | |
CVE-2024-51523 | Information management vulnerability in the Gallery module Impact: Successful exploitation of this v... | | |
CVE-2024-51524 | Permission control vulnerability in the Wi-Fi module Impact: Successful exploitation of this vulnera... | | |
CVE-2024-51525 | Permission control vulnerability in the clipboard module Impact: Successful exploitation of this vul... | | |
CVE-2024-51526 | Permission control vulnerability in the hidebug module Impact: Successful exploitation of this vulne... | | |
CVE-2024-51527 | Permission control vulnerability in the Gallery app Impact: Successful exploitation of this vulnerab... | | |
CVE-2024-51528 | Vulnerability of improper log printing in the Super Home Screen module Impact: Successful exploitati... | | |
CVE-2024-51529 | Data verification vulnerability in the battery module Impact: Successful exploitation of this vulne... | | |
CVE-2024-51530 | LaunchAnywhere vulnerability in the account module Impact: Successful exploitation of this vulnerabi... | | |
CVE-2024-51532 | Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument I... | | |
CVE-2024-51534 | Dell PowerProtect DD versions prior to DDOS 8.3.0.0, 7.10.1.50, and 7.13.1.20 contain a path travers... | | |
CVE-2024-51539 | The Dell Secure Connect Gateway (SCG) Application and Appliance, versions prior to 5.28, contains a ... | | |
CVE-2024-51540 | Dell ECS, versions prior to 3.8.1.3 contains an arithmetic overflow vulnerability exists in retentio... | | |
CVE-2024-51541 | Local File Inclusion | | |
CVE-2024-51542 | Configuration Download | | |
CVE-2024-51543 | Information Disclosure | | |
CVE-2024-51544 | Service Control | | |
CVE-2024-51545 | Username Enumeration | | |
CVE-2024-51546 | Credentails Disclosure | | |
CVE-2024-51547 | Credentials Disclosure - keys | | |
CVE-2024-51548 | Dangerous File Upload | | |
CVE-2024-51549 | Absolute Path Traversal | | |
CVE-2024-51550 | Data Validation / Sanitization | | |
CVE-2024-51551 | Default Credentials | | |
CVE-2024-51552 | Weak Password Storage | | |
CVE-2024-51553 | Predictable Filename | | |
CVE-2024-51554 | off-by-one-error | | |
CVE-2024-51555 | Force Change of Default Credentials | | |
CVE-2024-51556 | Sensitive Information Disclosure Vulnerability in Wave 2.0 | S | |
CVE-2024-51557 | No Rate Limiting Vulnerability in Wave 2.0 | S | |
CVE-2024-51558 | Brute Force Attack Vulnerability in Wave 2.0 | S | |
CVE-2024-51559 | Improper Access Control Vulnerability in Wave 2.0 | S | |
CVE-2024-51560 | Improper Error Handling Vulnerability in Wave 2.0 | S | |
CVE-2024-51561 | Authentication bypass Vulnerability in Aero | S | |
CVE-2024-51562 | bhyve(8) nvme_opc_get_log_page buffer over-read | | |
CVE-2024-51563 | bhyve(8) virtio_vq_recordon time-of-check to time-of-use race | | |
CVE-2024-51564 | bhyve(8) infinite loop in the hda audio driver | | |
CVE-2024-51565 | bhyve(8) hda driver buffer over-read | | |
CVE-2024-51566 | bhyve(8) NVMe driver to guest-induced infinite loops. | | |
CVE-2024-51567 | upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remot... | KEV E S | |
CVE-2024-51568 | CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUt... | | |
CVE-2024-51569 | Apache NimBLE: Lack of input sanitization leading to out-of-bound reads in Number of Completed Packets HCI event handler | S | |
CVE-2024-51570 | WordPress Easy Gallery plugin <= 1.4 - SQL Injection vulnerability | | |
CVE-2024-51571 | WordPress MasterBip para Elementor plugin <= 1.6.3 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51572 | WordPress LH QR Codes plugin <= 1.06 - Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51573 | WordPress ML Responsive Audio plugin <= 0.2 - Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51574 | WordPress Simple Goods plugin <= 0.1.3 - Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51575 | WordPress Extender All In One For Elementor plugin <= 1.0.3 - Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51576 | WordPress AMP Img Shortcode plugin <= 1.0.1 - Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51577 | WordPress bpmn.io plugin <= 1.0 - Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51578 | WordPress 3D Presentation plugin <= 1.0 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51579 | WordPress 5 Stars Rating Funnel plugin <= 1.4.01 - SQL Injection vulnerability | | |
CVE-2024-51580 | WordPress Clever Addons for Elementor plugin <= 2.2.1 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51581 | WordPress Restaurant & Cafe Addon for Elementor plugin <= 1.5.6 - Cross Site Scripting (XSS) vulnerability | S | |
CVE-2024-51582 | WordPress WP Hotel Booking plugin <= 2.1.4 - Local File Inclusion vulnerability | | |
CVE-2024-51583 | WordPress Kento Ads Rotator plugin <= 1.3 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51584 | WordPress Marquee Elementor with Posts plugin <= 1.2.0 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51585 | WordPress Sales Page Addon plugin <= 1.4.2 - Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51586 | WordPress Elementary Addons plugin <= 2.0.4 - Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51587 | WordPress Definitive Addons for Elementor plugin <= 1.5.16 - Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51588 | WordPress Super Addons for Elementor plugin <= 1.0 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51589 | WordPress Bigmart Elements plugin <= 1.0.3 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51590 | WordPress Hoo Addons for Elementor plugin <= 1.0.6 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51591 | WordPress Slicko plugin <= 1.2.0 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51592 | WordPress Meta Store Elements plugin <= 1.0.9 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51593 | WordPress Курс валют UAH plugin <= 2.0 - Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51594 | WordPress Gmap Point List plugin <= 1.1.2 - Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51595 | WordPress SKSDEV Toolkit plugin <= 1.0.0 - Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51596 | WordPress Business plugin <= 1.3 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51597 | WordPress ThemeShark Templates & Widgets for Elementor plugin <= 1.1.7 - Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51598 | WordPress Selar.co Widget plugin <= 1.2 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51599 | WordPress Simple Business Manager plugin <= 4.6.7.4 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51601 | WordPress Website price calculator plugin <= 4.1 - SQL Injection vulnerability | | |
CVE-2024-51602 | WordPress Simple Job Manager plugin <= 1.1 - SQL Injection vulnerability | | |
CVE-2024-51603 | WordPress NMR Strava activities plugin <= 1.0.6 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51604 | WordPress Media Modal plugin <= 1.0.2 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51605 | WordPress Genoo plugin <= 6.0.10 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51606 | WordPress Blrt WP Embed plugin <= 1.6.9 - SQL Injection vulnerability | | |
CVE-2024-51607 | WordPress Golf Tracker plugin <= 0.7 - SQL Injection vulnerability | | |
CVE-2024-51608 | WordPress AmaDiscount Plugin plugin <= 1.0 - SQL Injection vulnerability | | |
CVE-2024-51609 | WordPress Emoji Shortcode plugin <= 1.0.0 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51610 | WordPress Display Terms Shortcode plugin <= 1.0.4 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51611 | WordPress WP Feature Box plugin <= 0.1.3 - Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51612 | WordPress Reftagger Shortcode plugin <= 1.1 - Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51613 | WordPress TradeMe widgets plugin <= 1.2 - Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51614 | WordPress Aajoda Testimonials plugin <= 2.2.2 - Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51615 | WordPress WordPress Auction Plugin plugin <= 3.7 - SQL Injection vulnerability | | |
CVE-2024-51616 | WordPress AwesomePress plugin <= 1.0 - Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51617 | WordPress Clyp plugin <= 1.3 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51618 | WordPress Custom Admin Menu plugin <= 1.0.0 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51619 | WordPress Market 360 Viewer plugin <= 1.01 - SQL Injection vulnerability | | |
CVE-2024-51620 | WordPress Porsline plugin <= 1.0.2 - SQL Injection vulnerability | | |
CVE-2024-51621 | WordPress Download-Mirror-Counter plugin <= 1.1 - SQL Injection vulnerability | | |
CVE-2024-51622 | WordPress WP EASY RECIPE plugin <= 1.6 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51623 | WordPress WP EIS plugin <= 1.3.3 - SQL Injection vulnerability | | |
CVE-2024-51624 | WordPress Já-Já Pagamentos for WooCommerce plugin <= 1.3.0 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51625 | WordPress Quran Shortcode plugin <= 1.5 - SQL Injection vulnerability | | |
CVE-2024-51626 | WordPress Woocommerce Quote Calculator plugin <= 1.1 - SQL Injection vulnerability | | |
CVE-2024-51627 | WordPress Audio Comparison Lite plugin <= 3.4 - Stored Cross Site Scripting (XSS) vulnerability | S | |
CVE-2024-51628 | WordPress EzyOnlineBookings Online Booking System Widget plugin <= 1.3 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51629 | WordPress Header Footer Composer for Elementor plugin <= 1.0.4 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51630 | WordPress Responsive Flickr Gallery plugin <= 1.3.1 - CSRF to Stored XSS vulnerability | | |
CVE-2024-51631 | WordPress Sticky Social Bar plugin <= 2.0 - CSRF to Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51632 | WordPress SH Slideshow plugin <= 4.3 - CSRF to Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51633 | WordPress Simple Page Specific Sidebars plugin <= 2.14.1 - CSRF to Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51634 | WordPress Webriti Custom Login plugin <= 0.3 - CSRF to Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51635 | WordPress While Loading plugin <= 3.0 - CSRF to Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51636 | WordPress Plugin Name: GMO Social Connection plugin <= 1.2 - CSRF to Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51637 | WordPress Admin SMS Alert plugin <= 1.1.0 - CSRF to Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51638 | WordPress Awesome Shortcodes For Genesis plugin 1.1.8 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51639 | WordPress Naver Blog plugin <= 1.0 - CSRF to Stored XSS vulnerability | | |
CVE-2024-51640 | WordPress MDR Webmaster Tools plugin <= 1.1 - CSRF to Stored XSS vulnerability | | |
CVE-2024-51641 | WordPress Advanced PDF Generator plugin <= 0.4.0 - CSRF to Stored XSS vulnerability | | |
CVE-2024-51642 | WordPress Seo Free plugin <= 1.4 - CSRF to Stored XSS vulnerability | | |
CVE-2024-51643 | WordPress Amazon Associate Filter plugin <= 0.4 - CSRF to Stored XSS vulnerability | | |
CVE-2024-51644 | WordPress Addressbook plugin <= 1.1.3 - CSRF to Stored XSS vulnerability | | |
CVE-2024-51645 | WordPress ThemeFuse Maintenance Mode plugin <= 1.1.3 - CSRF to Stored XSS vulnerability | | |
CVE-2024-51646 | WordPress Saoshyant Element plugin <= 1.2 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51647 | WordPress Featured Posts Scroll plugin <= 1.25 - CSRF to Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51648 | WordPress e-shops plugin 1.0.3 - CSRF to Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51649 | WordPress Mobilize plugin <= 3.0.7 - CSRF to Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51650 | WordPress Random Featured Post plugin <= 1.1.3 - CSRF to Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51651 | WordPress CubeWP Forms plugin <= 1.1.5 - Broken Access Control vulnerability | | |
CVE-2024-51652 | WordPress Skip To plugin <= 2.0.0 - CSRF to Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51653 | WordPress UPDATE NOTIFICATIONS plugin <= 0.3.4 - CSRF to Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51654 | WordPress APK Downloader plugin <= 1.0.0 - CSRF to Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51655 | WordPress Custom Author URL plugin <= 2.0.1 - CSRF to Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51656 | WordPress Flash Show And Hide Box plugin <= 1.6 - CSRF to Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51657 | WordPress SmartLink Dynamic URLs plugin <= 1.1.0 - CSRF to Stored XSS vulnerability | S | |
CVE-2024-51658 | WordPress WP Course Manager plugin <= 1.3 - CSRF to Stored XSS vulnerability | | |
CVE-2024-51659 | WordPress Twitter @Anywhere Plus plugin <= 2.0 - CSRF to Stored XSS vulnerability | | |
CVE-2024-51660 | WordPress Easy Accordion Gutenberg Block plugin <= 1.2.3 - Broken Access Control vulnerability | S | |
CVE-2024-51661 | WordPress Media Library Assistant plugin <= 3.19 - Remote Code Execution (RCE) vulnerability | S | |
CVE-2024-51662 | WordPress Black Widgets For Elementor plugin <= 1.3.6 - Cross Site Scripting (XSS) vulnerability | S | |
CVE-2024-51663 | WordPress Bricksable for Bricks Builder plugin <= 1.6.59 - Cross Site Scripting (XSS) vulnerability | S | |
CVE-2024-51664 | WordPress Beds24 Online Booking plugin <= 2.0.25 - Cross Site Scripting (XSS) vulnerability | S | |
CVE-2024-51665 | WordPress Magical Addons For Elementor plugin <= 1.2.1 - Server Side Request Forgery (SSRF) vulnerability | S | |
CVE-2024-51666 | WordPress Tours plugin <= 1.0.0 - Broken Access Control vulnerability | S | |
CVE-2024-51667 | WordPress Paytium plugin <= 4.4.10 - Broken Access Control vulnerability | S | |
CVE-2024-51668 | WordPress MyCurator Content Curation plugin <= 3.78 - Cross Site Scripting (XSS) vulnerability | S | |
CVE-2024-51669 | WordPress Dynamic Widgets plugin <= 1.6.4 - Cross Site Request Forgery (CSRF) vulnerability | S | |
CVE-2024-51670 | WordPress JS Help Desk plugin <= 2.8.7 - Stored Cross Site Scripting (XSS) vulnerability | S | |
CVE-2024-51671 | WordPress Otter Blocks plugin <= 3.0.3 - Broken Access Control vulnerability | S | |
CVE-2024-51672 | WordPress BetterLinks plugin <= 2.1.7 - SQL Injection vulnerability | S | |
CVE-2024-51673 | WordPress HT Politic plugin <= 2.4.4 - Cross Site Scripting (XSS) vulnerability | S | |
CVE-2024-51674 | WordPress Sastra Essential Addons for Elementor plugin <= 1.0.5 - Cross Site Scripting (XSS) vulnerability | S | |
CVE-2024-51675 | WordPress aThemes Addons for Elementor plugin <= 1.0.7 - Cross Site Scripting (XSS) vulnerability | S | |
CVE-2024-51676 | WordPress Delisho plugin <= 1.0.6 - Cross Site Scripting (XSS) vulnerability | S | |
CVE-2024-51677 | WordPress Knowledge Base plugin <= 2.2.0 - Cross Site Scripting (XSS) vulnerability | S | |
CVE-2024-51678 | WordPress Elo Rating Shortcode plugin <= 1.0.3 - Cross Site Scripting (XSS) vulnerability | S | |
CVE-2024-51679 | WordPress Appointmind plugin <= 4.0.0 - CSRF to Stored XSS vulnerability | S | |
CVE-2024-51680 | WordPress Cresta Addons for Elementor plugin <= 1.0.9 - Stored Cross Site Scripting (XSS) vulnerability | S | |
CVE-2024-51681 | WordPress WP Pocket URLs plugin <= 1.0.3 - Cross Site Scripting (XSS) vulnerability | S | |
CVE-2024-51682 | WordPress HT Builder – WordPress Theme Builder for Elementor plugin <= 1.3.0 - Stored Cross Site Scripting (XSS) vulnerability | S | |
CVE-2024-51683 | WordPress Custom post type templates for Elementor plugin <= 1.10.1 - Stored Cross Site Scripting (XSS) vulnerability | S | |
CVE-2024-51684 | WordPress W3P SEO plugin < 1.8.6 - CSRF to Stored XSS vulnerability | S | |
CVE-2024-51685 | WordPress Accordion title for Elementor plugin <= 1.2.1 - Cross Site Scripting (XSS) vulnerability | S | |
CVE-2024-51686 | WordPress Manage User Columns plugin <= 1.0.5 - Cross Site Request Forgery (CSRF) vulnerability | S | |
CVE-2024-51687 | WordPress Platform.ly Official plugin <= 1.1.3 - CSRF to Stored XSS vulnerability | S | |
CVE-2024-51688 | WordPress FraudLabs Pro SMS Verification plugin <= 1.10.1 - CSRF to Stored XSS vulnerability | S | |
CVE-2024-51689 | WordPress CF7 WOW Styler plugin <= 1.6.8 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51690 | WordPress Wp Slide Categorywise plugin <= 1.1 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51691 | WordPress Admin Amplify plugin <= 1.3.0 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51692 | WordPress Bing Search API Integration plugin <= 0.3.3 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51693 | WordPress Search order by product SKU for WooCommerce plugin <= 0.2 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51694 | WordPress Geotagged Media plugin <= 0.3.0 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51695 | WordPress Fabrica Synced Pattern Instances plugin <= 1.0.8 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51696 | WordPress Content Syndication Toolkit Reader plugin <= 1.5 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51697 | WordPress Doofinder plugin <= 0.5.4 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51698 | WordPress Master Bar plugin <= 1.0 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51699 | WordPress Buooy Sticky Header plugin <= 0.5.2 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51700 | WordPress NAVER Analytics plugin <= 0.9 - CSRF to Stored XSS vulnerability | | |
CVE-2024-51701 | WordPress MG Post Contributors plugin <= 1.3. - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51702 | WordPress SrcSet Responsive Images for WordPress plugin <= 1.4 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51703 | WordPress WP-Basics plugin <= 2.0 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51704 | WordPress imPress plugin <= 0.1.4 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51705 | WordPress WP MMenu Lite plugin <= 1.0.0 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51706 | WordPress UW Freelancer plugin <= 0.1 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51707 | WordPress WP Visual Adverts plugin <= 2.3.0 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51708 | WordPress Narnoo Commerce Manager plugin <= 1.6.0 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51709 | WordPress TeleAdmin plugin <= 1.0.0 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51710 | WordPress Responsive Data Table plugin <= 1.3 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51711 | WordPress Saragna plugin <= 1.0 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51712 | WordPress Jigoshop plugin <= 1.4.0 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51713 | WordPress HQ60 Fidelity Card plugin <= 1.8 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51714 | WordPress User Password Reset plugin <= 1.0 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51715 | WordPress ClickWhale plugin <=2.4.1 - SQL Injection vulnerability | | |
CVE-2024-51716 | WordPress Twitter real time search scrolling plugin <= 7.0 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51717 | WordPress Ajax Content Filter plugin <= 1.0 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51718 | WordPress Simple Modal plugin <= 0.3.3 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51719 | WordPress Simplistic SEO plugin <= 2.3.0 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2024-51720 | Vulnerabilities in SecuSUITE Server Components Impact SecuSUITE | | |
CVE-2024-51721 | Vulnerabilities in SecuSUITE Server Components Impact SecuSUITE | | |
CVE-2024-51722 | Vulnerabilities in SecuSUITE Server Components Impact SecuSUITE | | |
CVE-2024-51723 | Vulnerability in Management Console Impacts BlackBerry AtHoc | | |
CVE-2024-51727 | Ruijie Reyee OS Premature Release of Resource During Expected Lifetime | S | |
CVE-2024-51728 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or... | R | |
CVE-2024-51729 | mm: use aligned address in copy_user_gigantic_page() | | |
CVE-2024-51734 | User data deletion by anoynmous users in Zope | | |
CVE-2024-51735 | Stored Cross-site Scripting to RCE on Osmedeus Web Server | | |
CVE-2024-51736 | Command execution hijack on Windows with Process class in symfony/process | | |
CVE-2024-51737 | RediSearch Integer Overflow with LIMIT or KNN arguments can lead to RCE | | |
CVE-2024-51738 | Sunshine improperly enforces pairing protocol request order | | |
CVE-2024-51739 | Users enumeration allowed through Rest API in Combodo iTop | M | |
CVE-2024-51740 | SSRF through arbitrary PHP class instantiation in the user portal in Combodo iTop | | |
CVE-2024-51741 | Redis allows denial-of-service due to malformed ACL selectors | | |
CVE-2024-51743 | Arbitrary File Write leading up to remote code execution (instructor accounts) | | |
CVE-2024-51744 | Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations in golang-jwt | | |
CVE-2024-51745 | Wasmtime doesn't fully sandbox all the Windows device filenames | | |
CVE-2024-51746 | Use of incorrect Rekor entries during verification in gitsign | | |
CVE-2024-51747 | Arbitrary File Read and Delete in kanboard | E | |
CVE-2024-51748 | Remote code execution through language setting in kanboard | E | |
CVE-2024-51749 | Element's thumbnails can be abused to misrepresent the content of an attachment | | |
CVE-2024-51750 | Element allows a malicious homeserver can modify events leading to unrenderable events or rooms | | |
CVE-2024-51751 | Arbitrary file read with File and UploadButton components in Gradio | | |
CVE-2024-51752 | Refresh tokens are logged when the debug flag is enabled in @workos-inc/authkit-nextjs | | |
CVE-2024-51753 | Refresh tokens are logged when the debug flag is enabled in @workos-inc/authkit-remix | | |
CVE-2024-51754 | Unguarded calls to __toString() when nesting an object into an array in Twig | | |
CVE-2024-51755 | Unguarded calls to __isset() and to array-accesses when the sandbox is enabled in Twig | | |
CVE-2024-51756 | cap-std doesn't fully sandbox all the Windows device filenames | | |
CVE-2024-51757 | Fixes security vulnerability that allowed for server side code to be executed by a |