NA - CVE-2024-28710 - Cross Site Scripting vulnerability in...
Cross Site Scripting vulnerability in LimeSurvey before 6.5.0+240319 allows a remote attacker to execute arbitrary code via a lack of input validation and output encoding in the Alert Widget's...
NA - CVE-2024-46040 - IoT Haat Smart Plug IH-IN-16A-S IH-IN-16A-S...
IoT Haat Smart Plug IH-IN-16A-S IH-IN-16A-S v5.16.1 suffers from Insufficient Session Expiration. The lack of validation of the authentication token at the IoT Haat during the Access Point Pairing...
NA - CVE-2024-46446 - Mecha CMS 3.0.0 is vulnerable to Directory...
Mecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct cookies and URIs that bypass user identity checks. Parameters can then be passed through the POST method, resulting...
NA - CVE-2024-9570 - A vulnerability was found in D-Link DIR-619L B1...
A vulnerability was found in D-Link DIR-619L B1 2.06 and classified as critical. Affected by this issue is the function formEasySetTimezone of the file /goform/formEasySetTimezone. The manipulation...
NA - CVE-2024-27458 - A potential security vulnerability has been...
A potential security vulnerability has been identified in the HP Hotkey Support software, which might allow local escalation of privilege. HP is releasing mitigation for the potential...
NA - CVE-2024-42831 - A reflected cross-site scripting (XSS)...
A reflected cross-site scripting (XSS) vulnerability in Elaine's Realtime CRM Automation v6.18.17 allows attackers to execute arbitrary JavaScript code in the web browser of a user via...