Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-10-04 CVE-2024-8149 Unspecified vulnerability in Esri Portal for Arcgis 11.1/11.2
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 11.1 and 11.2 which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.
network
low complexity
esri
6.1
2024-10-04 CVE-2024-47183 Incorrect Authorization vulnerability in Parseplatform Parse Server
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js.
network
low complexity
parseplatform CWE-863
8.1
2024-10-04 CVE-2024-47765 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Jgniecki Minecraft Motd Parser
Minecraft MOTD Parser is a PHP library to parse minecraft server motd.
network
low complexity
jgniecki CWE-80
6.1
2024-10-04 CVE-2024-47768 Missing Authorization vulnerability in Lifplatforms LIF Authentication Server
Lif Authentication Server is a server used by Lif to do various tasks regarding Lif accounts.
network
high complexity
lifplatforms CWE-862
8.1
2024-10-04 CVE-2024-47769 Relative Path Traversal vulnerability in Idurarapp Idurar
IDURAR is open source ERP CRM accounting invoicing software.
network
low complexity
idurarapp CWE-23
7.5
2024-10-04 CVE-2024-9410 Server-Side Request Forgery (SSRF) vulnerability in ADA
Ada.cx's Sentry configuration allowed for blind server-side request forgeries (SSRF) through the use of a data scraping endpoint.
network
low complexity
ada CWE-918
5.3
2024-10-04 CVE-2024-9514 Classic Buffer Overflow vulnerability in Dlink Dir-605L Firmware 2.13B01
A vulnerability was found in D-Link DIR-605L 2.13B01 BETA.
network
low complexity
dlink CWE-120
8.8
2024-10-04 CVE-2024-9515 Classic Buffer Overflow vulnerability in Dlink Dir-605L Firmware 2.13B01
A vulnerability was found in D-Link DIR-605L 2.13B01 BETA.
network
low complexity
dlink CWE-120
8.8
2024-10-04 CVE-2024-47652 Unspecified vulnerability in Shilpisoft Client Dashboard
This vulnerability exists in Shilpi Client Dashboard due to implementation of inadequate authentication mechanism in the login module wherein access to any users account is granted with just their corresponding mobile number.
network
high complexity
shilpisoft
8.1
2024-10-04 CVE-2024-47653 Unspecified vulnerability in Shilpisoft Client Dashboard
This vulnerability exists in Shilpi Client Dashboard due to lack of authorization for modification and cancellation requests through certain API endpoints.
network
low complexity
shilpisoft
6.5