|
249301
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The WPGlobus Translate Options plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing or incorrect nonce validation on th…
|
-
|
CVE-2024-9434
|
2024-11-1 21:57 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249302
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The Get Quote For Woocommerce – Request A Quote For Woocommerce plugin for WordPress is vulnerable to unauthorized access of Quote data due to a missing capability check on the ct_tepfw_wp_loaded fun…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2024-9430
|
2024-11-1 21:57 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249303
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.36.0 via the sub…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-9700
|
2024-11-1 21:57 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249304
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The AI Power: Complete AI Pack plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handle_image_upload' function in all versions up to, and includ…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-10392
|
2024-11-1 21:57 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249305
|
- |
|
-
|
-
|
Versions of the package lilconfig from 3.1.0 and before 3.1.1 are vulnerable to Arbitrary Code Execution due to the insecure usage of eval in the dynamicImport function. An attacker can exploit this …
|
-
|
CVE-2024-21537
|
2024-11-1 21:57 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249306
|
- |
|
-
|
-
|
Piwigo v14.5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit album function.
|
-
|
CVE-2024-48311
|
2024-11-1 21:57 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249307
|
- |
|
-
|
-
|
A vulnerability was found in Codezips Pet Shop Management System 1.0. It has been classified as critical. This affects an unknown part of the file birdsupdate.php. The manipulation of the argument id…
|
-
|
CVE-2024-10561
|
2024-11-1 21:57 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249308
|
- |
|
-
|
-
|
A vulnerability was found in SourceCodester Airport Booking Management System 1.0 and classified as critical. Affected by this issue is the function details of the component Passport Number Handler. …
|
CWE-120
Classic Buffer Overflow
|
CVE-2024-10559
|
2024-11-1 21:57 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249309
|
- |
|
-
|
-
|
JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData.
|
-
|
CVE-2024-48307
|
2024-11-1 21:57 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249310
|
- |
|
-
|
-
|
A vulnerability has been found in code-projects Blood Bank Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /file/updateprof…
|
CWE-352
Origin Validation Error
|
CVE-2024-10557
|
2024-11-1 21:57 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|