Vulnerabilities
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-10-29 | CVE-2024-47640 | Cross-site Scripting vulnerability in Wedevs WP ERP Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in weDevs WP ERP allows Reflected XSS.This issue affects WP ERP: from n/a through 1.13.2. | 6.1 |
2024-10-29 | CVE-2024-49632 | Cross-site Scripting vulnerability in Coralwebdesign CWD 3D Image Gallery Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Coral Web Design CWD 3D Image Gallery allows Reflected XSS.This issue affects CWD 3D Image Gallery: from n/a through 1.0. | 6.1 |
2024-10-29 | CVE-2024-49634 | Cross-site Scripting vulnerability in Rimonhabib BP Member Type Manager Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Rimon Habib BP Member Type Manager allows Reflected XSS.This issue affects BP Member Type Manager: from n/a through 1.01. | 6.1 |
2024-10-29 | CVE-2024-51075 | Cross-site Scripting vulnerability in PHPgurukul Online DJ Booking Management System 1.0 A Reflected Cross Site Scripting (XSS) vulnerability was found in /odms/admin/user-search.php in PHPGurukul Online DJ Booking Management System v1.0, which allows remote attackers to execute arbitrary code via the searchdata parameter. | 6.1 |
2024-10-29 | CVE-2024-51076 | Cross-site Scripting vulnerability in PHPgurukul Online DJ Booking Management System 1.0 A Reflected Cross Site Scripting (XSS) vulnerability was found in /odms/admin/booking-search.php in PHPGurukul Online DJ Booking Management System 1.0, which allows remote attackers to execute arbitrary code via the "searchdata" parameter. | 6.1 |
2024-10-29 | CVE-2024-9505 | Cross-site Scripting vulnerability in Fastlinemedia Beaver Builder The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in all versions up to, and including, 2.8.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-10-29 | CVE-2024-10458 | Unspecified vulnerability in Mozilla Thunderbird A permission leak could have occurred from a trusted site to an untrusted site via `embed` or `object` elements. | 7.5 |
2024-10-29 | CVE-2024-10459 | Use After Free vulnerability in Mozilla Thunderbird An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable crash. | 7.5 |
2024-10-29 | CVE-2024-10460 | Unspecified vulnerability in Mozilla Firefox and Thunderbird The origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. | 5.3 |
2024-10-29 | CVE-2024-10461 | Cross-site Scripting vulnerability in Mozilla Thunderbird In multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was not respected and did not force a download, which could allow XSS attacks. | 6.1 |