Aggregator
CVE-2024-48846 | ABB ASPECT-Enterprise/NEXUS/MATRIX up to 3.08.02 Setting cross-site request forgery
1 year 3 months ago
A vulnerability, which was classified as problematic, has been found in ABB ASPECT-Enterprise, NEXUS and MATRIX up to 3.08.02. This issue affects some unknown processing of the component Setting Handler. The manipulation leads to cross-site request forgery.
The identification of this vulnerability is CVE-2024-48846. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-53471 | WeGIA 3.2.0 meio_pagamento.php id/name cross site scripting
1 year 3 months ago
A vulnerability was found in WeGIA 3.2.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /configuracao/meio_pagamento.php. The manipulation of the argument id/name leads to cross site scripting.
This vulnerability is handled as CVE-2024-53471. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-10716 | Pegasystems Pega Infinity up to 24.2.0 Search cross site scripting
1 year 3 months ago
A vulnerability, which was classified as problematic, has been found in Pegasystems Pega Infinity up to 24.2.0. Affected by this issue is some unknown functionality of the component Search. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-10716. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-53472 | WeGIA 3.2.0 cross-site request forgery
1 year 3 months ago
A vulnerability, which was classified as problematic, was found in WeGIA 3.2.0. This affects an unknown part. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2024-53472. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-53470 | WeGIA 3.2.0 gateway_pagamento.php id/name cross site scripting
1 year 3 months ago
A vulnerability was found in WeGIA 3.2.0. It has been classified as problematic. Affected is an unknown function of the file /configuracao/gateway_pagamento.php. The manipulation of the argument id/name leads to cross site scripting.
This vulnerability is traded as CVE-2024-53470. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-11379 | Broadcast Plugin up to 51.01 on WordPress cross site scripting
1 year 3 months ago
A vulnerability was found in Broadcast Plugin up to 51.01 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-11379. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-10836 | Flixita Plugin up to 1.0.82 on WordPress id cross site scripting
1 year 3 months ago
A vulnerability classified as problematic has been found in Flixita Plugin up to 1.0.82 on WordPress. This affects an unknown part. The manipulation of the argument id leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-10836. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-9769 | Video Gallery Plugin up to 2.4.1 on WordPress cross site scripting
1 year 3 months ago
A vulnerability, which was classified as problematic, has been found in Video Gallery Plugin up to 2.4.1 on WordPress. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-9769. The attack may be initiated remotely. There is no exploit available.
vuldb.com
Auto-Generated Password Vulnerability In Sitevision Leaks Signing Key
1 year 3 months ago
A critical security flaw in Sitevision CMS versions 10.3.1 and older has exposed SAML authentication signing keys, enabling potential authentication bypass and session hijacking. The vulnerability, tracked as CVE-2022-35202, stems from weak auto-generated passwords protecting Java keystores, which could be extracted and brute-forced to compromise private keys. Sitevision, a widely adopted content management system in […]
The post Auto-Generated Password Vulnerability In Sitevision Leaks Signing Key appeared first on Cyber Security News.
Tushar Subhra Dutta
CVE-2024-49041 | Microsoft Edge up to 131.0.2903.63 the ui performs the wrong action (Nessus ID 212105)
1 year 3 months ago
A vulnerability, which was classified as problematic, has been found in Microsoft Edge. This issue affects some unknown processing. The manipulation leads to the ui performs the wrong action.
The identification of this vulnerability is CVE-2024-49041. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-11201 | myCred Plugin up to 2.7.5.2 on WordPress Shortcode mycred_send cross site scripting
1 year 3 months ago
A vulnerability classified as problematic was found in myCred Plugin up to 2.7.5.2 on WordPress. Affected by this vulnerability is the function mycred_send of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-11201. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-10879 | ForumWP Plugin up to 2.1.2 on WordPress cross site scripting
1 year 3 months ago
A vulnerability was found in ForumWP Plugin up to 2.1.2 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-10879. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-11204 | ForumWP Plugin up to 2.1.2 on WordPress URL Parameter cross site scripting
1 year 3 months ago
A vulnerability was found in ForumWP Plugin up to 2.1.2 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality of the component URL Parameter Handler. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-11204. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-2776 | Campcodes Online Marriage Registration System 1.0 /admin/search.php searchdata sql injection
1 year 3 months ago
A vulnerability, which was classified as critical, was found in Campcodes Online Marriage Registration System 1.0. Affected is an unknown function of the file /admin/search.php. The manipulation of the argument searchdata leads to sql injection.
This vulnerability is traded as CVE-2024-2776. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-2943 | Campcodes Online Examination System 1.0 deleteExamExe.php id sql injection
1 year 3 months ago
A vulnerability has been found in Campcodes Online Examination System 1.0 and classified as critical. This vulnerability affects unknown code of the file /adminpanel/admin/query/deleteExamExe.php. The manipulation of the argument id leads to sql injection.
This vulnerability was named CVE-2024-2943. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-2944 | Campcodes Online Examination System 1.0 deleteCourseExe.php id sql injection
1 year 3 months ago
A vulnerability was found in Campcodes Online Examination System 1.0 and classified as critical. This issue affects some unknown processing of the file /adminpanel/admin/query/deleteCourseExe.php. The manipulation of the argument id leads to sql injection.
The identification of this vulnerability is CVE-2024-2944. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-2945 | Campcodes Online Examination System 1.0 updateExaminee.php id sql injection
1 year 3 months ago
A vulnerability was found in Campcodes Online Examination System 1.0. It has been classified as critical. Affected is an unknown function of the file /adminpanel/admin/facebox_modal/updateExaminee.php. The manipulation of the argument id leads to sql injection.
This vulnerability is traded as CVE-2024-2945. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-33553 | 8theme XStore Core Plugin up to 5.3.5 on WordPress deserialization
1 year 3 months ago
A vulnerability, which was classified as problematic, has been found in 8theme XStore Core Plugin up to 5.3.5 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to deserialization.
This vulnerability is handled as CVE-2024-33553. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-33558 | 8theme XStore Core Plugin up to 5.3.5 on WordPress authorization
1 year 3 months ago
A vulnerability was found in 8theme XStore Core Plugin up to 5.3.5 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to missing authorization.
This vulnerability is handled as CVE-2024-33558. The attack may be launched remotely. There is no exploit available.
vuldb.com