Aggregator
唯一安全厂商!360安全智能体获权威机构推荐稳居行业第一选择
12 minutes 19 seconds hence
安全客
Microsoft 警告:Node.js 恶意广告肆虐,加密交易用户信息安全告急
6 minutes 13 seconds hence
安全客
黑客利用 MMC 脚本发动攻击,部署 MysterySnail RAT 威胁系统安全
8 minutes 15 seconds ago
安全客
CVE-2024-1910 | Categorify Plugin up to 1.0.7.4 on WordPress categorifyAjaxClearCategory cross-site request forgery (ID 3034410)
1 hour ago
A vulnerability, which was classified as problematic, was found in Categorify Plugin up to 1.0.7.4 on WordPress. Affected is the function categorifyAjaxClearCategory. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2024-1910. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-1919 | SourceCodester Online Job Portal 1.0 Manage Walkin Page ManageWalkin.php Job Title cross site scripting
1 hour ago
A vulnerability classified as problematic was found in SourceCodester Online Job Portal 1.0. This vulnerability affects unknown code of the file /Employer/ManageWalkin.php of the component Manage Walkin Page. The manipulation of the argument Job Title leads to cross site scripting.
This vulnerability was named CVE-2024-1919. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2023-7203 | Smart Forms Plugin up to 2.6.86 on WordPress AJAX Action cross-site request forgery
1 hour ago
A vulnerability was found in Smart Forms Plugin up to 2.6.86 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality of the component AJAX Action Handler. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2023-7203. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-26143 | Ruby on Rails up to 7.0.8.0/7.1.3.0 cross site scripting (GHSA-9822-6m93-xqf4)
1 hour ago
A vulnerability was found in Ruby on Rails up to 7.0.8.0/7.1.3.0. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-26143. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-26471 | zhimengzhe iBarn 1.5 offer.php Search cross site scripting
1 hour ago
A vulnerability was found in zhimengzhe iBarn 1.5. It has been declared as problematic. This vulnerability affects unknown code of the file offer.php. The manipulation of the argument Search leads to cross site scripting.
This vulnerability was named CVE-2024-26471. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-1922 | SourceCodester Online Job Portal 1.0 Manage Job Page /Employer/ManageJob.php Qualification/Description cross site scripting
1 hour ago
A vulnerability has been found in SourceCodester Online Job Portal 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /Employer/ManageJob.php of the component Manage Job Page. The manipulation of the argument Qualification/Description leads to cross site scripting.
This vulnerability is known as CVE-2024-1922. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-26473 | KLiK SocialMediaWebsite 1.0.1 poll.php poll cross site scripting
1 hour ago
A vulnerability classified as problematic has been found in KLiK SocialMediaWebsite 1.0.1. Affected is an unknown function of the file poll.php. The manipulation of the argument poll leads to cross site scripting.
This vulnerability is traded as CVE-2024-26473. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-26472 | KLiK SocialMediaWebsite 1.0.1 offer.php selector/validator cross site scripting
1 hour ago
A vulnerability was found in KLiK SocialMediaWebsite 1.0.1. It has been rated as problematic. This issue affects some unknown processing of the file offer.php. The manipulation of the argument selector/validator leads to cross site scripting.
The identification of this vulnerability is CVE-2024-26472. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-1943 | Yuki Plugin up to 1.3.14 on WordPress Theme Setting cross-site request forgery (ID 218603)
1 hour ago
A vulnerability was found in Yuki Plugin up to 1.3.14 on WordPress. It has been rated as problematic. This issue affects some unknown processing of the component Theme Setting Handler. The manipulation leads to cross-site request forgery.
The identification of this vulnerability is CVE-2024-1943. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2020-5509 | PHPGurukul Car Rental Project 1.0 File Upload Profile Image unrestricted upload (ID 155925 / EDB-52243)
1 hour 16 minutes ago
A vulnerability classified as critical has been found in PHPGurukul Car Rental Project 1.0. This affects an unknown part of the component File Upload. The manipulation as part of Profile Image leads to unrestricted upload.
This vulnerability is uniquely identified as CVE-2020-5509. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2013-5093 | Graphite up to 0.9.10 renderLocalView code injection (EDB-27752 / Nessus ID 70241)
1 hour 24 minutes ago
A vulnerability was found in Graphite up to 0.9.10. It has been rated as critical. Affected by this issue is the function renderLocalView. The manipulation leads to code injection.
This vulnerability is handled as CVE-2013-5093. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-26301 | HPE Aruba ClearPass Policy Manager up to 6.9.13/6.10.8/6.11.6/6.12.0 Web-based Management Interface information disclosure (ARUBA-PSA-2024-001)
1 hour 32 minutes ago
A vulnerability was found in HPE Aruba ClearPass Policy Manager up to 6.9.13/6.10.8/6.11.6/6.12.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Web-based Management Interface. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2024-26301. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-26542 | Bonitasoft up to 7.14.7/7.15.6/8.0.2/9.0.1 Groups Display Name cross site scripting
1 hour 32 minutes ago
A vulnerability classified as problematic has been found in Bonitasoft up to 7.14.7/7.15.6/8.0.2/9.0.1. This affects an unknown part. The manipulation of the argument Groups Display Name leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-26542. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-26299 | HPE Aruba ClearPass Policy Manager up to 6.9.13/6.10.8/6.11.6/6.12.0 Web-based Management Interface cross site scripting (ARUBA-PSA-2024-001)
1 hour 32 minutes ago
A vulnerability, which was classified as problematic, was found in HPE Aruba ClearPass Policy Manager up to 6.9.13/6.10.8/6.11.6/6.12.0. Affected is an unknown function of the component Web-based Management Interface. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-26299. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-0768 | Envo Elementor Templates & Widgets for WooCommerce Plugin ajax_theme_activation cross-site request forgery
1 hour 32 minutes ago
A vulnerability, which was classified as problematic, was found in Envo Elementor Templates & Widgets for WooCommerce Plugin up to 1.4.4 on WordPress. This affects the function ajax_theme_activation. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2024-0768. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-26300 | HPE Aruba ClearPass Policy Manager up to 6.9.13/6.10.8/6.11.6/6.12.0 Guest Interface cross site scripting (ARUBA-PSA-2024-001)
1 hour 32 minutes ago
A vulnerability, which was classified as problematic, has been found in HPE Aruba ClearPass Policy Manager up to 6.9.13/6.10.8/6.11.6/6.12.0. This issue affects some unknown processing of the component Guest Interface. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-26300. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com