Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-11-04 CVE-2024-51685 Cross-site Scripting vulnerability in Migaweb Accordion Title for Elementor
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Gangolf Accordion title for Elementor allows Stored XSS.This issue affects Accordion title for Elementor: from n/a through 1.2.1.
network
low complexity
migaweb CWE-79
4.8
2024-11-04 CVE-2024-45164 Incorrect Authorization vulnerability in Akamai Secure Internet Access Enterprise Threatavert 19.2.0.2
Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, has incorrect authorization controls for the Admin functionality on the ThreatAvert Policy page.
network
low complexity
akamai CWE-863
7.1
2024-11-04 CVE-2024-50523 Unrestricted Upload of File with Dangerous Type vulnerability in Rainbow-Link ALL Post Contact Form
Unrestricted Upload of File with Dangerous Type vulnerability in RainbowLink Inc.
network
low complexity
rainbow-link CWE-434
critical
9.8
2024-11-04 CVE-2024-50525 Unrestricted Upload of File with Dangerous Type vulnerability in Helloprint
Unrestricted Upload of File with Dangerous Type vulnerability in Helloprint Plug your WooCommerce into the largest catalog of customized print products from Helloprint allows Upload a Web Shell to a Web Server.This issue affects Plug your WooCommerce into the largest catalog of customized print products from Helloprint: from n/a through 2.0.2.
network
low complexity
helloprint CWE-434
critical
9.8
2024-11-04 CVE-2024-50526 Unrestricted Upload of File with Dangerous Type vulnerability in Lindeni Multi Purpose Mail Form
Unrestricted Upload of File with Dangerous Type vulnerability in mahlamusa Multi Purpose Mail Form allows Upload a Web Shell to a Web Server.This issue affects Multi Purpose Mail Form: from n/a through 1.0.2.
network
low complexity
lindeni CWE-434
critical
9.8
2024-11-04 CVE-2024-50527 Unrestricted Upload of File with Dangerous Type vulnerability in Stacksmarket Stacks Mobile APP Builder
Unrestricted Upload of File with Dangerous Type vulnerability in Stacks Stacks Mobile App Builder allows Upload a Web Shell to a Web Server.This issue affects Stacks Mobile App Builder: from n/a through 5.2.3.
network
low complexity
stacksmarket CWE-434
critical
9.8
2024-11-04 CVE-2024-50528 Unspecified vulnerability in Stacksmarket Stacks Mobile APP Builder
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Stacks Stacks Mobile App Builder allows Retrieve Embedded Sensitive Data.This issue affects Stacks Mobile App Builder: from n/a through 5.2.3.
network
low complexity
stacksmarket
7.5
2024-11-04 CVE-2024-50529 Unrestricted Upload of File with Dangerous Type vulnerability in Rudrainnovative Training - Courses
Unrestricted Upload of File with Dangerous Type vulnerability in Rudra Innnovative Software Training – Courses allows Upload a Web Shell to a Web Server.This issue affects Training – Courses: from n/a through 2.0.1.
network
low complexity
rudrainnovative CWE-434
8.8
2024-11-04 CVE-2024-50530 Unrestricted Upload of File with Dangerous Type vulnerability in Myriadsolutionz Stars Smtp Mailer
Unrestricted Upload of File with Dangerous Type vulnerability in Myriad Solutionz Stars SMTP Mailer allows Upload a Web Shell to a Web Server.This issue affects Stars SMTP Mailer: from n/a through 1.7.
network
low complexity
myriadsolutionz CWE-434
8.8
2024-11-04 CVE-2024-50531 Unrestricted Upload of File with Dangerous Type vulnerability in Carrcommunications Rsvpmaker
Unrestricted Upload of File with Dangerous Type vulnerability in David F.
network
low complexity
carrcommunications CWE-434
critical
9.8