|
251871
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Kama SpamBlock plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST values in all versions up to, and including, 1.8.2 due to insufficient input sanitization and output…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9647
|
2024-10-16 11:15 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251872
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The SEO Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post meta in versions up to, and including, 1.9 due to insufficient input sanitization and output escaping on use…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9521
|
2024-10-16 11:15 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251873
|
8.1 |
HIGH
Network
|
-
|
-
|
The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.4.4. This is due to the appp_reset_passwo…
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2024-9305
|
2024-10-16 11:15 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251874
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The UltimateAI plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.8.3. This is due to insufficient verification on the user being supplied in the 'ultimat…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2024-9105
|
2024-10-16 11:15 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251875
|
5.6 |
MEDIUM
Network
|
-
|
-
|
The UltimateAI plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.8.3. This is due to the improper empty value check and a missing default activated v…
|
CWE-703
Improper Check or Handling of Exceptional Conditions
|
CVE-2024-9104
|
2024-10-16 11:15 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251876
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Smart Online Order for Clover plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in al…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8787
|
2024-10-16 11:15 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251877
|
7.3 |
HIGH
Local
|
microsoft
|
windows_server_2016 windows_server_2019 windows_server_2022 windows_11_22h2 windows_11_21h2 windows_10_22h2 windows_10_21h2 windows_10_1809 windows_10_1607 windows_11_23h2<…
|
Summary
Microsoft was notified that an elevation of privilege vulnerability exists in Windows Update, potentially enabling an attacker with basic user privileges to reintroduce previously mitigated v…
|
NVD-CWE-Other
|
CVE-2024-38202
|
2024-10-16 11:15 |
2024-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251878
|
- |
|
apple
|
safari
|
Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted XML document.
|
CWE-399
Resource Management Errors
|
CVE-2010-0048
|
2024-10-16 06:35 |
2010-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251879
|
- |
|
apple
|
safari
|
Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to "HTML obj…
|
CWE-399
Resource Management Errors
|
CVE-2010-0047
|
2024-10-16 06:35 |
2010-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251880
|
- |
|
apple
|
mac_os_x mac_os_x_server
|
Buffer overflow in Image RAW in Apple Mac OS X 10.5.8 and 10.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted DNG image.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-0037
|
2024-10-16 06:35 |
2010-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|