Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2024-11-15 CVE-2024-10311 Unspecified vulnerability in Cmorillas1 External Database Based Actions 0.1
The External Database Based Actions plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.1.
network
low complexity
cmorillas1
8.8
2024-11-14 CVE-2024-50968 Unspecified vulnerability in Adonesevangelista Agri-Trading Online Shopping System 1.0
A business logic vulnerability exists in the Add to Cart function of itsourcecode Agri-Trading Online Shopping System 1.0, which allows remote attackers to manipulate the quant parameter when adding a product to the cart.
network
low complexity
adonesevangelista
7.5
2024-11-14 CVE-2024-3760 Unspecified vulnerability in Lunary
In lunary-ai/lunary version 1.2.7, there is a lack of rate limiting on the forgot password page, leading to an email bombing vulnerability.
network
low complexity
lunary
7.5
2024-11-14 CVE-2024-3379 Incorrect Authorization vulnerability in Lunary
In lunary-ai/lunary versions 1.2.2 through 1.2.6, an incorrect authorization vulnerability allows unprivileged users to re-generate the private key for projects they do not have access to.
network
low complexity
lunary CWE-863
8.1
2024-11-14 CVE-2024-3501 Insecure Storage of Sensitive Information vulnerability in Lunary
In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability exists due to the inclusion of single-use tokens in the responses of `GET /v1/users/me` and `GET /v1/users/me/org` API endpoints.
network
low complexity
lunary CWE-922
8.1
2024-11-14 CVE-2024-3502 Insecure Storage of Sensitive Information vulnerability in Lunary
In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability exists where account recovery hashes of users are inadvertently exposed to unauthorized actors.
network
low complexity
lunary CWE-922
8.1
2024-11-14 CVE-2024-50824 SQL Injection vulnerability in Lopalopa E-Learning Management System 1.0
A SQL Injection vulnerability was found in /admin/class.php in kashipara E-learning Management System Project 1.0 via the class_name parameter.
network
low complexity
lopalopa CWE-89
7.2
2024-11-14 CVE-2024-50825 SQL Injection vulnerability in Lopalopa E-Learning Management System 1.0
A SQL Injection vulnerability was found in /admin/school_year.php in kashipara E-learning Management System Project 1.0 via the school_year parameter.
network
low complexity
lopalopa CWE-89
7.2
2024-11-14 CVE-2024-50826 SQL Injection vulnerability in Lopalopa E-Learning Management System 1.0
A SQL Injection vulnerability was found in /admin/add_content.php in kashipara E-learning Management System Project 1.0 via the title and content parameters.
network
low complexity
lopalopa CWE-89
7.2
2024-11-14 CVE-2024-50827 SQL Injection vulnerability in Lopalopa E-Learning Management System 1.0
A SQL Injection vulnerability was found in /admin/add_subject.php in kashipara E-learning Management System Project 1.0 via the subject_code parameter.
network
low complexity
lopalopa CWE-89
7.2