Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-11-09 CVE-2024-51599 Cross-site Scripting vulnerability in Russellalbin Simple Business Manager
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Russell Albin Simple Business Manager allows Stored XSS.This issue affects Simple Business Manager: from n/a through 4.6.7.4.
network
low complexity
russellalbin CWE-79
5.4
2024-11-09 CVE-2024-51603 Cross-site Scripting vulnerability in Mirceatm NMR Strava Activities
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Mircea N.
network
low complexity
mirceatm CWE-79
5.4
2024-11-09 CVE-2024-51604 Cross-site Scripting vulnerability in Jumpstartcreatives Media Modal
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Carlo Andro Mabugay Media Modal allows DOM-Based XSS.This issue affects Media Modal: from n/a through 1.0.2.
network
low complexity
jumpstartcreatives CWE-79
5.4
2024-11-09 CVE-2024-51605 Cross-site Scripting vulnerability in Genoo
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Genoo, LLC Genoo allows DOM-Based XSS.This issue affects Genoo: from n/a through 6.0.10.
network
low complexity
genoo CWE-79
5.4
2024-11-09 CVE-2024-51606 SQL Injection vulnerability in Blrt WP Embed
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Blrt Blrt WP Embed allows SQL Injection.This issue affects Blrt WP Embed: from n/a through 1.6.9.
network
low complexity
blrt CWE-89
8.8
2024-11-09 CVE-2024-51608 SQL Injection vulnerability in Pluginhandy Amadiscount 1.0
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pluginhandy AmaDiscount allows SQL Injection.This issue affects AmaDiscount: from n/a through 1.0.
network
low complexity
pluginhandy CWE-89
8.8
2024-11-09 CVE-2024-51609 Cross-site Scripting vulnerability in Elsner Emoji Shortcode
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Elsner Technologies Pvt.
network
low complexity
elsner CWE-79
5.4
2024-11-09 CVE-2024-51610 Cross-site Scripting vulnerability in Seothemes Display Terms Shortcode
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SEO Themes Display Terms Shortcode allows Stored XSS.This issue affects Display Terms Shortcode: from n/a through 1.0.4.
network
low complexity
seothemes CWE-79
5.4
2024-11-09 CVE-2024-51662 Cross-site Scripting vulnerability in Modernaweb Black Widgets for Elementor
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Modernaweb Studio Black Widgets For Elementor allows Stored XSS.This issue affects Black Widgets For Elementor: from n/a through 1.3.6.
network
low complexity
modernaweb CWE-79
5.4
2024-11-09 CVE-2024-51663 Cross-site Scripting vulnerability in Bricksable for Bricks Builder
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bricksable Bricksable for Bricks Builder allows Stored XSS.This issue affects Bricksable for Bricks Builder: from n/a through 1.6.59.
network
low complexity
bricksable CWE-79
4.8