|
249411
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in Lukas Huser EKC Tournament Manager allows Upload a Web Shell to a Web Server.This issue affects EKC Tournament Manager: from n/a through 2.2.1.
|
CWE-352
Origin Validation Error
|
CVE-2024-49674
|
2024-11-1 21:57 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249412
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher allows Code Injection.This issue affects Podlove Podcast Publisher: from n/a through 4.1.13.
|
CWE-352
Origin Validation Error
|
CVE-2024-43984
|
2024-11-1 21:57 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249413
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in WPMobile.App allows Stored XSS.This issue affects WPMobile.App: from n/a through 11.48.
|
CWE-352
Origin Validation Error
|
CVE-2024-43933
|
2024-11-1 21:57 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249414
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in eyecix JobSearch allows Cross Site Request Forgery.This issue affects JobSearch: from n/a through 2.5.3.
|
-
|
CVE-2024-43930
|
2024-11-1 21:57 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249415
|
- |
|
-
|
-
|
HCL AppScan Source <= 10.6.0 does not properly validate a TLS/SSL certificate for an executable.
|
-
|
CVE-2024-30149
|
2024-11-1 21:57 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249416
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The WP Simple Anchors Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpanchor shortcode in all versions up to, and including, 1.0.0 due to insufficient input…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9446
|
2024-11-1 21:57 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249417
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The WPGlobus Translate Options plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing or incorrect nonce validation on th…
|
-
|
CVE-2024-9434
|
2024-11-1 21:57 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249418
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The Get Quote For Woocommerce – Request A Quote For Woocommerce plugin for WordPress is vulnerable to unauthorized access of Quote data due to a missing capability check on the ct_tepfw_wp_loaded fun…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2024-9430
|
2024-11-1 21:57 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249419
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.36.0 via the sub…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-9700
|
2024-11-1 21:57 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249420
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The AI Power: Complete AI Pack plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handle_image_upload' function in all versions up to, and includ…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-10392
|
2024-11-1 21:57 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|