NA - CVE-2024-45229 - The Versa Director offers REST APIs for...
The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen, banner display, and device registration, do not require authentication....
NA - CVE-2024-46654 - A stored cross-site scripting (XSS)...
A stored cross-site scripting (XSS) vulnerability in the Add Scheduled Task module of Maccms10 v2024.1000.4040 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
NA - CVE-2024-47061 - Plate is a javascript toolkit that makes it...
Plate is a javascript toolkit that makes it easier for you to develop with Slate, a popular framework for building text editors. One longstanding feature of Plate is the ability to add custom DOM...
NA - CVE-2024-47062 - Navidrome is an open source web-based music...
Navidrome is an open source web-based music collection server and streamer. Navidrome automatically adds parameters in the URL to SQL queries. This can be exploited to access information by adding...
NA - CVE-2024-45793 - Confidant is a open source secret management...
Confidant is a open source secret management service that provides user-friendly storage and access to secrets. The following endpoints are subject to a cross site scripting vulnerability: GET...
NA - CVE-2024-46640 - SeaCMS 13.2 has a remote code execution...
SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function is not executed during execution, allowing...