|
251441
|
4.8 |
MEDIUM
Network
|
aftabhusain
|
category_and_taxonomy_meta_fields
|
The Category and Taxonomy Meta Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image meta field value in the 'wpaft_add_meta_textinput' function in versions up to, an…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9590
|
2024-10-30 01:07 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251442
|
4.8 |
MEDIUM
Network
|
aftabhusain
|
category_and_taxonomy_meta_fields
|
The Category and Taxonomy Meta Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'new_meta_name' parameter in the 'wpaft_option_page' function in versions up to, and in…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9589
|
2024-10-30 01:07 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251443
|
9.8 |
CRITICAL
Network
|
pluginus
|
wordpress_meta_data_and_taxonomies_filter
|
Improper Control of Generation of Code ('Code Injection') vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF) allows Code Injection.This issue affects WordPress Meta Data and…
|
CWE-94
Code Injection
|
CVE-2024-50450
|
2024-10-30 01:05 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251444
|
7.2 |
HIGH
Network
|
royal-elementor-addons
|
royal_elementor_addons
|
Improper Restriction of XML External Entity Reference vulnerability in WP Royal Royal Elementor Addons allows XML Injection.This issue affects Royal Elementor Addons: from n/a through 1.3.980.
|
CWE-611
XXE
|
CVE-2024-50442
|
2024-10-30 01:04 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251445
|
4.8 |
MEDIUM
Network
|
aftabhusain
|
category_and_taxonomy_image
|
The Category and Taxonomy Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_category_image' parameter in versions up to, and including, 1.0.0 due to insufficient input…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9591
|
2024-10-30 01:04 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251446
|
8.8 |
HIGH
Network
|
wpclever
|
wpc_shop_as_a_customer_for_woocommerce
|
Deserialization of Untrusted Data vulnerability in WPClever WPC Shop as a Customer for WooCommerce allows Object Injection.This issue affects WPC Shop as a Customer for WooCommerce: from n/a through …
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-50416
|
2024-10-30 01:02 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251447
|
8.8 |
HIGH
Network
|
kibokolabs
|
namaste\!_lms
|
Deserialization of Untrusted Data vulnerability in Kiboko Labs Namaste! LMS allows Object Injection.This issue affects Namaste! LMS: from n/a through 2.6.3.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-50408
|
2024-10-30 01:01 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251448
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Implement bounds check for stream encoder creation in DCN401
'stream_enc_regs' array is an array of dcn10_stream…
|
CWE-129
Improper Validation of Array Index
|
CVE-2024-49970
|
2024-10-30 00:57 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251449
|
6.5 |
MEDIUM
Network
|
metagauss
|
profilegrid
|
Missing Authorization vulnerability in ProfileGrid User Profiles ProfileGrid.This issue affects ProfileGrid: from n/a through 5.9.3.
|
CWE-862
Missing Authorization
|
CVE-2024-49273
|
2024-10-30 00:48 |
2024-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251450
|
9.1 |
CRITICAL
Network
|
openrefine
|
butterfly
|
The OpenRefine fork of the MIT Simile Butterfly server is a modular web application framework. The Butterfly framework uses the `java.net.URL` class to refer to (what are expected to be) local resour…
|
CWE-22
Path Traversal
|
CVE-2024-47883
|
2024-10-30 00:38 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|