Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-10-29 CVE-2024-47640 Cross-site Scripting vulnerability in Wedevs WP ERP
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in weDevs WP ERP allows Reflected XSS.This issue affects WP ERP: from n/a through 1.13.2.
network
low complexity
wedevs CWE-79
6.1
2024-10-29 CVE-2024-49632 Cross-site Scripting vulnerability in Coralwebdesign CWD 3D Image Gallery
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Coral Web Design CWD 3D Image Gallery allows Reflected XSS.This issue affects CWD 3D Image Gallery: from n/a through 1.0.
network
low complexity
coralwebdesign CWE-79
6.1
2024-10-29 CVE-2024-49634 Cross-site Scripting vulnerability in Rimonhabib BP Member Type Manager
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Rimon Habib BP Member Type Manager allows Reflected XSS.This issue affects BP Member Type Manager: from n/a through 1.01.
network
low complexity
rimonhabib CWE-79
6.1
2024-10-29 CVE-2024-51075 Cross-site Scripting vulnerability in PHPgurukul Online DJ Booking Management System 1.0
A Reflected Cross Site Scripting (XSS) vulnerability was found in /odms/admin/user-search.php in PHPGurukul Online DJ Booking Management System v1.0, which allows remote attackers to execute arbitrary code via the searchdata parameter.
network
low complexity
phpgurukul CWE-79
6.1
2024-10-29 CVE-2024-51076 Cross-site Scripting vulnerability in PHPgurukul Online DJ Booking Management System 1.0
A Reflected Cross Site Scripting (XSS) vulnerability was found in /odms/admin/booking-search.php in PHPGurukul Online DJ Booking Management System 1.0, which allows remote attackers to execute arbitrary code via the "searchdata" parameter.
network
low complexity
phpgurukul CWE-79
6.1
2024-10-29 CVE-2024-9505 Cross-site Scripting vulnerability in Fastlinemedia Beaver Builder
The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in all versions up to, and including, 2.8.4.2 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
fastlinemedia CWE-79
5.4
2024-10-29 CVE-2024-10458 Unspecified vulnerability in Mozilla Thunderbird
A permission leak could have occurred from a trusted site to an untrusted site via `embed` or `object` elements.
network
low complexity
mozilla
7.5
2024-10-29 CVE-2024-10459 Use After Free vulnerability in Mozilla Thunderbird
An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable crash.
network
low complexity
mozilla CWE-416
7.5
2024-10-29 CVE-2024-10460 Unspecified vulnerability in Mozilla Firefox and Thunderbird
The origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`.
network
low complexity
mozilla
5.3
2024-10-29 CVE-2024-10461 Cross-site Scripting vulnerability in Mozilla Thunderbird
In multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was not respected and did not force a download, which could allow XSS attacks.
network
low complexity
mozilla CWE-79
6.1