|
251491
|
4.3 |
MEDIUM
Network
|
paytium
|
paytium
|
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized API key update due to a missing capability check on the paytium_sw_save_api_keys function in versions …
|
CWE-862
Missing Authorization
|
CVE-2023-7289
|
2024-10-18 02:29 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251492
|
5.4 |
MEDIUM
Network
|
paytium
|
paytium
|
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized subscription cancellation due to a missing capability check on the pt_cancel_subscription function in …
|
CWE-862
Missing Authorization
|
CVE-2023-7287
|
2024-10-18 02:28 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251493
|
4.3 |
MEDIUM
Network
|
paytium
|
paytium
|
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_profile_preference function in versi…
|
CWE-862
Missing Authorization
|
CVE-2023-7288
|
2024-10-18 02:27 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251494
|
6.8 |
MEDIUM
Physics
|
microsoft
|
windows_server_2022_23h2 windows_10_1809 windows_server_2019 windows_11_21h2 windows_10_21h2 windows_11_22h2 windows_10_22h2 windows_11_23h2 windows_11_24h2
|
Windows Mobile Broadband Driver Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-43543
|
2024-10-18 02:23 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251495
|
6.7 |
MEDIUM
Local
|
google
|
android
|
In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed.
|
CWE-77
Command Injection
|
CVE-2024-39438
|
2024-10-18 02:19 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251496
|
6.7 |
MEDIUM
Local
|
google
|
android
|
In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed.
|
CWE-77
Command Injection
|
CVE-2024-39437
|
2024-10-18 02:18 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251497
|
6.7 |
MEDIUM
Local
|
google
|
android
|
In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed.
|
CWE-77
Command Injection
|
CVE-2024-39436
|
2024-10-18 02:16 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251498
|
7.5 |
HIGH
Network
|
microsoft
|
windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2022_23h2 windows_server_2022 windows_server_2019
|
Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-43544
|
2024-10-18 02:16 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251499
|
4.3 |
MEDIUM
Adjacent
|
gotenna
|
gotenna
|
The goTenna Pro ATAK Plugin does not encrypt callsigns in messages. It
is advised to not use sensitive information in callsigns when using this
and previous versions of the plugin. Update to curren…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2024-45838
|
2024-10-18 02:15 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251500
|
6.5 |
MEDIUM
Adjacent
|
gotenna
|
gotenna
|
The goTenna Pro ATAK Plugin does not use SecureRandom when generating
passwords for sharing cryptographic keys. The random function in use
makes it easier for attackers to brute force this password…
|
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
|
CVE-2024-45723
|
2024-10-18 02:15 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|