Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-11-30 CVE-2024-12001 Cross-site Scripting vulnerability in Anisha Wazifa System 1.0
A vulnerability classified as problematic has been found in code-projects Wazifa System 1.0.
network
low complexity
anisha CWE-79
5.4
2024-11-30 CVE-2024-12002 NULL Pointer Dereference vulnerability in Tenda products
A vulnerability classified as problematic was found in Tenda FH451, FH1201, FH1202 and FH1206 up to 20241129.
network
low complexity
tenda CWE-476
6.5
2024-11-30 CVE-2024-12000 Cross-site Scripting vulnerability in Code-Projects Blood Bank System 1.0
A vulnerability was found in code-projects Blood Bank System 1.0.
network
low complexity
code-projects CWE-79
5.4
2024-11-30 CVE-2024-11998 SQL Injection vulnerability in Farmacia Project Farmacia 1.0
A vulnerability was found in code-projects Farmacia 1.0.
network
low complexity
farmacia-project CWE-89
7.5
2024-11-30 CVE-2024-11996 Cross-site Scripting vulnerability in Anisha Farmacia 1.0
A vulnerability was found in code-projects Farmacia 1.0 and classified as problematic.
network
low complexity
anisha CWE-79
5.4
2024-11-30 CVE-2024-11997 Cross-site Scripting vulnerability in Anisha Farmacia 1.0
A vulnerability was found in code-projects Farmacia 1.0.
network
low complexity
anisha CWE-79
5.4
2024-11-30 CVE-2024-11252 The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the heateor_mastodon_share parameter in all versions up to, and including, 3.3.69 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
6.1
2024-11-29 CVE-2024-11995 Cross-site Scripting vulnerability in Anisha Farmacia 1.0
A vulnerability has been found in code-projects Farmacia 1.0 and classified as problematic.
network
low complexity
anisha CWE-79
6.1
2024-11-29 CVE-2024-49803 OS Command Injection vulnerability in IBM Security Verify Access
IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.
network
low complexity
ibm CWE-78
8.8
2024-11-29 CVE-2024-49804 Unspecified vulnerability in IBM Security Verify Access
IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a locally authenticated non-administrative user to escalate their privileges due to unnecessary permissions used to perform certain tasks.
local
low complexity
ibm
7.8