Aggregator
CVE-2024-41368 | MiczFlor RPi-Jukebox-RFID 2.7.0 inc.setWlanIpMail.php code injection
5 months 1 week ago
A vulnerability, which was classified as critical, was found in MiczFlor RPi-Jukebox-RFID 2.7.0. Affected is an unknown function of the file htdocs\inc.setWlanIpMail.php. The manipulation leads to code injection.
This vulnerability is traded as CVE-2024-41368. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-41370 | Organizr 1.90 chat/setlike.php sql injection
5 months 1 week ago
A vulnerability, which was classified as critical, has been found in Organizr 1.90. This issue affects some unknown processing of the file chat/setlike.php. The manipulation leads to sql injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
The identification of this vulnerability is CVE-2024-41370. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-41372 | Organizr 1.90 chat/settyping.php sql injection
5 months 1 week ago
A vulnerability classified as critical was found in Organizr 1.90. This vulnerability affects unknown code of the file chat/settyping.php. The manipulation leads to sql injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability was named CVE-2024-41372. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2024-41348 | openflights 5234b5b php/alsearch.php cross site scripting
5 months 1 week ago
A vulnerability classified as problematic has been found in openflights 5234b5b. This affects an unknown part of the file php/alsearch.php. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-41348. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-41371 | Organizr 1.90 api.php cross site scripting
5 months 1 week ago
A vulnerability was found in Organizr 1.90. It has been rated as problematic. Affected by this issue is some unknown functionality of the file api.php. The manipulation leads to cross site scripting. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is handled as CVE-2024-41371. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-41347 | openflights 5234b5b php/settings.php cross site scripting
5 months 1 week ago
A vulnerability was found in openflights 5234b5b. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file php/settings.php. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-41347. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-41358 | phpipam 1.6 import-load-data.php cross site scripting
5 months 1 week ago
A vulnerability was found in phpipam 1.6. It has been classified as problematic. Affected is an unknown function of the file app\admin\import-export\import-load-data.php. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-41358. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-41346 | openflights 5234b5b php/submit.php cross site scripting
5 months 1 week ago
A vulnerability was found in openflights 5234b5b and classified as problematic. This issue affects some unknown processing of the file php/submit.php. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-41346. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-8319 | Tourfic Plugin up to 2.11.20 on WordPress cross-site request forgery
5 months 1 week ago
A vulnerability has been found in Tourfic Plugin up to 2.11.20 on WordPress and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2024-8319. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-5879 | HubSpot Plugin up to 11.1.22 on WordPress HubSpot Meeting Widget cross site scripting
5 months 1 week ago
A vulnerability, which was classified as problematic, was found in HubSpot Plugin up to 11.1.22 on WordPress. This affects an unknown part of the component HubSpot Meeting Widget. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-5879. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-4401 | Elementor Addon Elements Plugin up to 1.13.5 on WordPress id/eae_slider_animation cross site scripting
5 months 1 week ago
A vulnerability, which was classified as problematic, has been found in Elementor Addon Elements Plugin up to 1.13.5 on WordPress. Affected by this issue is some unknown functionality. The manipulation of the argument id/eae_slider_animation leads to cross site scripting.
This vulnerability is handled as CVE-2024-4401. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-5024 | Memberpress Plugin up to 1.11.29 on WordPress mepr_screenname/mepr_key cross site scripting
5 months 1 week ago
A vulnerability classified as problematic was found in Memberpress Plugin up to 1.11.29 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation of the argument mepr_screenname/mepr_key leads to cross site scripting.
This vulnerability is known as CVE-2024-5024. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-5061 | Enfold Plugin up to 6.0.3 on WordPress wrapper_class/class cross site scripting
5 months 1 week ago
A vulnerability classified as problematic has been found in Enfold Plugin up to 6.0.3 on WordPress. Affected is an unknown function. The manipulation of the argument wrapper_class/class leads to cross site scripting.
This vulnerability is traded as CVE-2024-5061. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-5784 | Tutor LMS Pro Plugin up to 2.7.2 on WordPress resource injection
5 months 1 week ago
A vulnerability was found in Tutor LMS Pro Plugin up to 2.7.2 on WordPress. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to improper control of resource identifiers.
The identification of this vulnerability is CVE-2024-5784. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-2694 | Betheme Theme up to 27.5.6 on WordPress code injection
5 months 1 week ago
A vulnerability was found in Betheme Theme up to 27.5.6 on WordPress. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to code injection.
This vulnerability was named CVE-2024-2694. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-3998 | Betheme Theme up to 27.5.6 on WordPress Shortcode cross site scripting
5 months 1 week ago
A vulnerability was found in Betheme Theme up to 27.5.6 on WordPress. It has been classified as problematic. This affects an unknown part of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-3998. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-8016 | Events Calendar Pro Plugin up to 7.0.2 on WordPress code injection
5 months 1 week ago
A vulnerability was found in Events Calendar Pro Plugin up to 7.0.2 on WordPress and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to code injection.
This vulnerability is handled as CVE-2024-8016. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-6672 | Progress WhatsUp Gold getMonitorJoin sql injection (ZDI-24-1187)
5 months 1 week ago
A vulnerability has been found in Progress WhatsUp Gold and classified as critical. Affected by this vulnerability is the function getMonitorJoin. The manipulation leads to sql injection.
This vulnerability is known as CVE-2024-6672. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-6671 | Progress WhatsUp Gold GetStatisticalMonitorList sql injection (ZDI-24-1186)
5 months 1 week ago
A vulnerability, which was classified as critical, was found in Progress WhatsUp Gold. Affected is the function GetStatisticalMonitorList. The manipulation leads to sql injection.
This vulnerability is traded as CVE-2024-6671. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com