Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-10-28 CVE-2024-10448 Cross-Site Request Forgery (CSRF) vulnerability in Fabianros Blood Bank Management System 1.0
A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank Management System 1.0.
network
low complexity
fabianros CWE-352
6.5
2024-10-28 CVE-2024-10447 SQL Injection vulnerability in Projectworlds Online Time Table Generator 1.0
A vulnerability classified as critical was found in Project Worlds Online Time Table Generator 1.0.
network
low complexity
projectworlds CWE-89
8.8
2024-10-28 CVE-2024-50463 Open Redirect vulnerability in Sunshinephotocart Sunshine Photo Cart
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WP Sunshine Sunshine Photo Cart.This issue affects Sunshine Photo Cart: from n/a through 3.2.9.
network
low complexity
sunshinephotocart CWE-601
6.1
2024-10-28 CVE-2024-50465 SQL Injection vulnerability in Squirrly Premium SEO Pack
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP SEO – Calin Vingan Premium SEO Pack allows SQL Injection.This issue affects Premium SEO Pack: from n/a through 1.6.001.
network
low complexity
squirrly CWE-89
6.5
2024-10-28 CVE-2024-50470 Cross-site Scripting vulnerability in Themes4Wp Youtube External Subtitles
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themes4WP Themes4WP YouTube External Subtitles allows Stored XSS.This issue affects Themes4WP YouTube External Subtitles: from n/a through 1.0.
network
low complexity
themes4wp CWE-79
5.4
2024-10-28 CVE-2024-50471 Cross-site Scripting vulnerability in Checklist Trip Plan
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Checklist Trip Plan allows Stored XSS.This issue affects Trip Plan: from n/a through 1.0.10.
network
low complexity
checklist CWE-79
5.4
2024-10-28 CVE-2024-50472 Cross-site Scripting vulnerability in Amilia Store
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Martin Drapeau Amilia Store allows Stored XSS.This issue affects Amilia Store: from n/a through 2.9.8.
network
low complexity
amilia CWE-79
5.4
2024-10-28 CVE-2024-50478 Improper Authentication vulnerability in Swoopnow 1-Click Login: Passwordless Authentication 1.4.5
Authentication Bypass by Primary Weakness vulnerability in Swoop 1-Click Login: Passwordless Authentication allows Authentication Bypass.This issue affects 1-Click Login: Passwordless Authentication: 1.4.5.
network
low complexity
swoopnow CWE-287
critical
9.8
2024-10-28 CVE-2024-50479 SQL Injection vulnerability in Mansurahamed Woocommerce Quote Calculator
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mansur Ahamed Woocommerce Quote Calculator allows Blind SQL Injection.This issue affects Woocommerce Quote Calculator: from n/a through 1.1.
network
low complexity
mansurahamed CWE-89
critical
9.8
2024-10-28 CVE-2024-50483 Authorization Bypass Through User-Controlled Key vulnerability in Tareqhasan Meetup
Authorization Bypass Through User-Controlled Key vulnerability in Meetup allows Privilege Escalation.This issue affects Meetup: from n/a through 0.1.
network
low complexity
tareqhasan CWE-639
critical
9.8