Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-10-17 CVE-2024-49229 Cross-Site Request Forgery (CSRF) vulnerability in Arifnezami Better Author BIO
Cross-Site Request Forgery (CSRF) vulnerability in Arif Nezami Better Author Bio allows Cross-Site Scripting (XSS).This issue affects Better Author Bio: from n/a through 2.7.10.11.
network
low complexity
arifnezami CWE-352
6.1
2024-10-17 CVE-2024-49237 Cross-Site Request Forgery (CSRF) vulnerability in Ahmetimamoglu Ahmeti WP Timeline
Cross-Site Request Forgery (CSRF) vulnerability in Ahmet Imamoglu Ahmeti Wp Timeline allows Stored XSS.This issue affects Ahmeti Wp Timeline: from n/a through 5.1.
network
low complexity
ahmetimamoglu CWE-352
6.1
2024-10-17 CVE-2024-10072 SQL Injection vulnerability in Esafenet CDG 5
A vulnerability, which was classified as critical, has been found in ESAFENET CDG 5.
network
low complexity
esafenet CWE-89
8.8
2024-10-17 CVE-2024-10073 Code Injection vulnerability in Informatik.Hu-Berlin Flair 0.14.0
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0.
network
high complexity
informatik-hu-berlin CWE-94
7.5
2024-10-17 CVE-2024-10071 SQL Injection vulnerability in Esafenet CDG 5
A vulnerability classified as critical was found in ESAFENET CDG 5.
network
low complexity
esafenet CWE-89
8.8
2024-10-17 CVE-2024-10069 SQL Injection vulnerability in Esafenet CDG 5
A vulnerability was found in ESAFENET CDG 5.
network
low complexity
esafenet CWE-89
8.8
2024-10-17 CVE-2024-10070 SQL Injection vulnerability in Esafenet CDG 5
A vulnerability classified as critical has been found in ESAFENET CDG 5.
network
low complexity
esafenet CWE-89
8.8
2024-10-17 CVE-2024-47459 NULL Pointer Dereference vulnerability in Adobe Substance 3D Sampler 4.2.1
Substance3D - Sampler versions 4.5 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to an application denial-of-service (DoS) condition.
local
low complexity
adobe CWE-476
5.5
2024-10-17 CVE-2024-9683 A vulnerability was found in Quay, which allows successful authentication even when a truncated password version is provided.
network
high complexity
CWE-305
4.8
2024-10-17 CVE-2005-10003 OS Command Injection vulnerability in Mikexstudios Xcomic
A vulnerability classified as critical has been found in mikexstudios Xcomic up to 0.8.2.
network
low complexity
mikexstudios CWE-78
critical
9.8