|
250391
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Extensions by HocWP Team plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.2.3.2. This is due to missing validation on the user being supplied in the…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2024-9930
|
2024-10-28 22:58 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250392
|
- |
|
-
|
-
|
The Editorial Assistant by Sovrn plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_zemanta_set_featured_image' function in version…
|
-
|
CVE-2024-9626
|
2024-10-28 22:58 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250393
|
4.9 |
MEDIUM
Network
|
-
|
-
|
The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to generic SQL Injection via the order_by parameter in all versions up to, and including, 5.4.6 due to …
|
CWE-89
SQL Injection
|
CVE-2024-9475
|
2024-10-28 22:58 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250394
|
5.5 |
MEDIUM
Network
|
-
|
-
|
The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Stored Cross-Site Scripting via poll settings in all versions up to, and including, 5.4.6 due to insu…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9462
|
2024-10-28 22:58 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250395
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The PriPre plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.4.11 due to insufficient input sanitization and output escapi…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9454
|
2024-10-28 22:58 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250396
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Comparison Widget in all versions up to, and including, 3.2.9 due to insufficient inpu…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10091
|
2024-10-28 22:58 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250397
|
- |
|
-
|
-
|
An issue was found in funadmin 5.0.2. The selectfiles method in \backend\controller\sys\Attachh.php directly stores the passed parameters and values into the param parameter without filtering, result…
|
-
|
CVE-2024-48228
|
2024-10-28 22:58 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250398
|
- |
|
-
|
-
|
Werkzeug is a Web Server Gateway Interface web application library. On Python < 3.11 on Windows, os.path.isabs() does not catch UNC paths like //server/share. Werkzeug's safe_join() relies on this ch…
|
CWE-22
Path Traversal
|
CVE-2024-49766
|
2024-10-28 22:58 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250399
|
- |
|
-
|
-
|
Cross Site Scripting vulnerability in Blood Bank v.1 allows a remote attacker to execute arbitrary code via a crafted script to the login.php component.
|
-
|
CVE-2024-48654
|
2024-10-28 22:58 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250400
|
- |
|
-
|
-
|
File Upload vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the admin_class.php component.
|
-
|
CVE-2024-48581
|
2024-10-28 22:58 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|