|
250121
|
4.9 |
MEDIUM
Network
|
pimcore
|
pimcore
|
Pimcore is an open source data and experience management platform. When a PortalUserObject is connected to a PimcoreUser and "Use Pimcore Backend Password" is set to true, the change password functio…
|
NVD-CWE-Other
|
CVE-2024-49370
|
2024-11-7 07:31 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250122
|
8.8 |
HIGH
Network
|
vitaliibryl
|
switch_user
|
Authentication Bypass Using an Alternate Path or Channel vulnerability in Vitalii Bryl iBryl Switch User allows Authentication Bypass.This issue affects iBryl Switch User: from n/a through 1.0.1.
|
NVD-CWE-Other
|
CVE-2024-49675
|
2024-11-7 07:24 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250123
|
5.4 |
MEDIUM
Network
|
migaweb
|
custom_post_type_templates_for_elementor
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Gangolf Custom post type templates for Elementor allows Stored XSS.This issue affe…
|
CWE-79
Cross-site Scripting
|
CVE-2024-51683
|
2024-11-7 07:12 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250124
|
5.4 |
MEDIUM
Network
|
hasthemes
|
ht_builder
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in HasThemes HT Builder – WordPress Theme Builder for Elementor allows Stored XSS.This issue …
|
CWE-79
Cross-site Scripting
|
CVE-2024-51682
|
2024-11-7 07:12 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250125
|
5.4 |
MEDIUM
Network
|
coderevolution
|
wp_pocket_urls
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CodeRevolution WP Pocket URLs allows Stored XSS.This issue affects WP Pocket URLs: from n/…
|
CWE-79
Cross-site Scripting
|
CVE-2024-51681
|
2024-11-7 07:11 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250126
|
5.4 |
MEDIUM
Network
|
crestaproject
|
cresta_addons_for_elementor
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CrestaProject – Rizzo Andrea Cresta Addons for Elementor allows Stored XSS.This issue affe…
|
CWE-79
Cross-site Scripting
|
CVE-2024-51680
|
2024-11-7 07:10 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250127
|
5.4 |
MEDIUM
Network
|
timelord
|
elo_rating_shortcode
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Marcel Pol Elo Rating Shortcode allows Stored XSS.This issue affects Elo Rating Shortcode:…
|
CWE-79
Cross-site Scripting
|
CVE-2024-51678
|
2024-11-7 07:10 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250128
|
5.4 |
MEDIUM
Network
|
webberzone
|
knowledge_base
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WebberZone Knowledge Base allows Stored XSS.This issue affects Knowledge Base: from n/a th…
|
CWE-79
Cross-site Scripting
|
CVE-2024-51677
|
2024-11-7 07:10 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250129
|
8.8 |
HIGH
Network
|
mansurahamed
|
woocommerce_quote_calculator
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mansur Ahamed Woocommerce Quote Calculator allows Blind SQL Injection.This issue affects Woocomme…
|
CWE-89
SQL Injection
|
CVE-2024-51626
|
2024-11-7 07:10 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250130
|
7.2 |
HIGH
Network
|
wpdeveloper
|
betterlinks
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPDeveloper BetterLinks allows SQL Injection.This issue affects BetterLinks: from n/a through 2.1…
|
CWE-89
SQL Injection
|
CVE-2024-51672
|
2024-11-7 07:08 |
2024-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|