Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-11-09 CVE-2024-9270 The Lenxel Core for Lenxel(LNX) LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping.
network
low complexity
6.4
2024-11-09 CVE-2024-9775 Cross-site Scripting vulnerability in Shtheme Anih
The Anih - Creative Agency WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2024 due to an incomplete blacklist, insufficient input sanitization, and output escaping.
network
low complexity
shtheme CWE-79
4.8
2024-11-08 CVE-2024-52000 Cross-site Scripting vulnerability in Combodo Itop
Combodo iTop is a simple, web based IT Service Management tool.
network
low complexity
combodo CWE-79
6.1
2024-11-08 CVE-2024-52001 Unspecified vulnerability in Combodo Itop
Combodo iTop is a simple, web based IT Service Management tool.
network
low complexity
combodo
4.3
2024-11-08 CVE-2024-52002 Cross-Site Request Forgery (CSRF) vulnerability in Combodo Itop
Combodo iTop is a simple, web based IT Service Management tool.
network
low complexity
combodo CWE-352
8.8
2024-11-08 CVE-2024-11026 Use of Hard-coded Credentials vulnerability in Free-Now Freenow 12.10.0
A vulnerability was found in Intelligent Apps Freenow App 12.10.0 on Android.
network
high complexity
free-now CWE-798
7.4
2024-11-08 CVE-2024-40239 Unspecified vulnerability in Hitbytes Life 17.5.0
An incorrect access control issue in Life: Personal Diary, Journal android app 17.5.0 allows a physically proximate attacker to escalate privileges via the fingerprint authentication function.
low complexity
hitbytes
6.8
2024-11-08 CVE-2024-40240 Unspecified vulnerability in Homeserve 3.3.4
An incorrect access control issue in HomeServe Home Repair' android app - 3.3.4 allows a physically proximate attacker to escalate privileges via the fingerprint authentication function.
low complexity
homeserve
6.8
2024-11-08 CVE-2024-51030 SQL Injection vulnerability in Oretnom23 CAB Management System 1.0
A SQL injection vulnerability in manage_client.php and view_cab.php of Sourcecodester Cab Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter, leading to unauthorized access and potential compromise of sensitive data within the database.
network
low complexity
oretnom23 CWE-89
6.5
2024-11-08 CVE-2024-51031 Cross-site Scripting vulnerability in Oretnom23 CAB Management System 1.0
A Cross-site Scripting (XSS) vulnerability in manage_account.php in Sourcecodester Cab Management System 1.0 allows remote authenticated users to inject arbitrary web scripts via the "First Name," "Middle Name," and "Last Name" fields.
network
low complexity
oretnom23 CWE-79
5.4