Aggregator
CVE-2025-1553 | pankajindevops scale up to 3633544a00245d3df88b6d13d9b3dd0f411be7f6 /scale/project goal cross site scripting
9 months 3 weeks ago
A vulnerability was found in pankajindevops scale up to 3633544a00245d3df88b6d13d9b3dd0f411be7f6. It has been classified as problematic. Affected is an unknown function of the file /scale/project. The manipulation of the argument goal leads to cross site scripting.
This vulnerability is traded as CVE-2025-1553. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
vuldb.com
Submit #491216: https://github.com/pankajindevops/scale Scale latest Stored Cross Site Scripting [Accepted]
9 months 3 weeks ago
Submit #491216 / VDB-296502
0xNayel
CVE-2024-47256 | 2N Access Commander up to 2N 1.14 information disclosure
9 months 3 weeks ago
A vulnerability was found in 2N Access Commander up to 2N 1.14. It has been classified as problematic. This affects an unknown part. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2024-47256. An attack has to be approached locally. There is no exploit available.
vuldb.com
CVE-2024-13417 | 2N OS up to 2.45 RFID Reader uncaught exception
9 months 3 weeks ago
A vulnerability was found in 2N OS up to 2.45. It has been rated as problematic. This issue affects some unknown processing of the component RFID Reader. The manipulation leads to uncaught exception.
The identification of this vulnerability is CVE-2024-13417. It is possible to launch the attack on the physical device. There is no exploit available.
vuldb.com
CVE-2024-47258 | 2N Access Commander up to 2.1 channel accessible
9 months 3 weeks ago
A vulnerability classified as critical has been found in 2N Access Commander up to 2.1. Affected is an unknown function. The manipulation leads to channel accessible by non-endpoint.
This vulnerability is traded as CVE-2024-47258. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-22209 | joomsky JS Jobs Component up to 1.4.3 on Joomla Employer Payment History Search searchpaymentstatus sql injection
9 months 3 weeks ago
A vulnerability classified as critical was found in joomsky JS Jobs Component up to 1.4.3 on Joomla. Affected by this vulnerability is an unknown functionality of the component Employer Payment History Search. The manipulation of the argument searchpaymentstatus leads to sql injection.
This vulnerability is known as CVE-2025-22209. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-22208 | joomsky JS Jobs Component 1.1.5-1.4.3 on Joomla filter_email sql injection
9 months 3 weeks ago
A vulnerability, which was classified as critical, was found in joomsky JS Jobs Component 1.1.5-1.4.3 on Joomla. This affects an unknown part. The manipulation of the argument filter_email leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-22208. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-53802 | FuturioWP Futurio Extra Plugin up to 2.0.14 on WordPress cross site scripting
9 months 3 weeks ago
A vulnerability has been found in FuturioWP Futurio Extra Plugin up to 2.0.14 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-53802. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-53812 | Jacques Malgrange WP GeoNames Plugin up to 1.8 on WordPress cross site scripting
9 months 3 weeks ago
A vulnerability was found in Jacques Malgrange WP GeoNames Plugin up to 1.8 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-53812. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-53820 | Captivate Audio Captivate Sync Plugin up to 2.0.22 on WordPress cross site scripting
9 months 3 weeks ago
A vulnerability was found in Captivate Audio Captivate Sync Plugin up to 2.0.22 on WordPress. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-53820. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-53821 | NotFound Pie Register Premium Plugin up to 3.8.3.2 on WordPress cross site scripting
9 months 3 weeks ago
A vulnerability classified as problematic has been found in NotFound Pie Register Premium Plugin up to 3.8.3.2 on WordPress. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-53821. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-54206 | Urban Base Z-Downloads Plugin up to 1.11.7 on WordPress cross site scripting
9 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in Urban Base Z-Downloads Plugin up to 1.11.7 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-54206. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-54208 | Joni Halabi Block Controller Plugin up to 1.4.2 on WordPress cross site scripting
9 months 3 weeks ago
A vulnerability was found in Joni Halabi Block Controller Plugin up to 1.4.2 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-54208. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-53823 | Posimyth The Plus Addons for Elementor Page Builder Lite Plugin cross site scripting
9 months 3 weeks ago
A vulnerability classified as problematic was found in Posimyth The Plus Addons for Elementor Page Builder Lite Plugin up to 5.6.14 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-53823. The attack can be launched remotely. There is no exploit available.
vuldb.com
DoD Contractor Pays $11.2M over False Cyber Certifications Claims
9 months 3 weeks ago
Health Net Federal Services has agreed to pay over $11m over alleged false cybersecurity reporting
从开放重定向到远程代码执行
9 months 3 weeks ago
声明:文章中涉及的程序(方法)可能带有攻击性,仅供安全研究与教学之用,读者将其信息做其他用途,由用户承担全部法
LockBit атакует: в Хакасии бизнес стал жертвой кибервымогателей
9 months 3 weeks ago
Хакеры через AnyDesk заразили систему.
CVE-2024-13416 | 2N OS up to 2.45 API log file
9 months 3 weeks ago
A vulnerability was found in 2N OS up to 2.45. It has been declared as problematic. This vulnerability affects unknown code of the component API. The manipulation leads to sensitive information in log files.
This vulnerability was named CVE-2024-13416. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-1208 | code-projects Wazifa System 1.0 /Profile.php postcontent cross site scripting
9 months 3 weeks ago
A vulnerability was found in code-projects Wazifa System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /Profile.php. The manipulation of the argument postcontent leads to cross site scripting.
The identification of this vulnerability is CVE-2025-1208. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com