|
251961
|
6.1 |
MEDIUM
Network
|
wpfactory
|
maximum_products_per_user_for_woocommerce
|
The Maximum Products per User for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versi…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9205
|
2024-10-15 23:16 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251962
|
5.4 |
MEDIUM
Network
|
secretlab
|
marketing_and_seo_booster
|
The Marketing and SEO Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.9.10 due to insufficient input sanitizatio…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9066
|
2024-10-15 23:14 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251963
|
5.4 |
MEDIUM
Network
|
namogo
|
elementor_inline_svg
|
The Elementor Inline SVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.2.0 due to insufficient input sanitization and …
|
CWE-79
Cross-site Scripting
|
CVE-2024-9064
|
2024-10-15 23:11 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251964
|
9.1 |
CRITICAL
Network
|
indutny
|
elliptic
|
The verify function in lib/elliptic/eddsa/index.js in the Elliptic package before 6.5.6 for Node.js omits "sig.S().gte(sig.eddsa.curve.n) || sig.S().isNeg()" validation.
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2024-48949
|
2024-10-15 23:07 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251965
|
6.1 |
MEDIUM
Network
|
idiom
|
easy_social_share_buttons
|
The Easy Social Share Buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and i…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8729
|
2024-10-15 22:40 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251966
|
4.3 |
MEDIUM
Network
|
brevo
|
newsletter\ _smtp\ _email_marketing_and_subscribe
|
The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.87. …
|
CWE-352
Origin Validation Error
|
CVE-2024-8477
|
2024-10-15 22:30 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251967
|
7.5 |
HIGH
Network
|
checkmk
|
checkmk
|
Information leakage in mknotifyd in Checkmk before 2.3.0p18, 2.2.0p36, 2.1.0p49 and in 2.0.0p39 (EOL) allows attacker to get potentially sensitive data
|
CWE-200
Information Exposure
|
CVE-2024-6747
|
2024-10-15 22:22 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251968
|
6.1 |
MEDIUM
Network
|
limesurvey
|
limesurvey
|
Cross Site Scripting vulnerability in LimeSurvey before 6.5.12+240611 allows a remote attacker to execute arbitrary code via a crafted script to the title and comment fields.
|
CWE-79
Cross-site Scripting
|
CVE-2024-28709
|
2024-10-15 22:19 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251969
|
6.1 |
MEDIUM
Network
|
limesurvey
|
limesurvey
|
Cross Site Scripting vulnerability in LimeSurvey before 6.5.0+240319 allows a remote attacker to execute arbitrary code via a lack of input validation and output encoding in the Alert Widget's messag…
|
CWE-79
Cross-site Scripting
|
CVE-2024-28710
|
2024-10-15 22:18 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251970
|
- |
|
-
|
-
|
An issue in sbondCo Watcharr v.1.43.0 allows a remote attacker to execute arbitrary code and escalate privileges via the Change Password function.
|
-
|
CVE-2024-48827
|
2024-10-15 21:58 |
2024-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|