|
257261
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Oxygen Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the oxy_save_css_from_admin AJAX action in all versions up to, and incl…
|
-
|
CVE-2024-6688
|
2024-08-27 14:15 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257262
|
- |
|
-
|
-
|
Rejected reason: Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that the issue does not pose a secu…
|
-
|
CVE-2024-7989
|
2024-08-27 06:15 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257263
|
- |
|
-
|
-
|
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accid…
|
-
|
CVE-2024-8188
|
2024-08-27 05:15 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257264
|
9.8 |
CRITICAL
Network
|
givewp
|
givewp
|
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.1 via deserialization of untrusted input fr…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-5932
|
2024-08-27 03:34 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257265
|
6.5 |
MEDIUM
Network
|
ibm
|
global_configuration_management
|
IBM Global Configuration Management 7.0.2 and 7.0.3 could allow an authenticated user to archive a global baseline due to improper access controls.
|
NVD-CWE-Other
|
CVE-2024-41773
|
2024-08-27 03:33 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257266
|
6.5 |
MEDIUM
Network
|
ghost
|
ghost
|
Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information. Th…
|
CWE-287
Improper Authentication
|
CVE-2024-43409
|
2024-08-27 03:31 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257267
|
8.8 |
HIGH
Network
|
lfedge
|
ekuiper
|
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. A user could utilize and exploit SQL Injection to allow the execution of …
|
CWE-89
SQL Injection
|
CVE-2024-43406
|
2024-08-27 03:30 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257268
|
9.8 |
CRITICAL
Network
|
megacord
|
megabot
|
MEGABOT is a fully customized Discord bot for learning and fun. The `/math` command and functionality of MEGABOT versions < 1.5.0 contains a remote code execution vulnerability due to a Python `eval(…
|
CWE-94
Code Injection
|
CVE-2024-43404
|
2024-08-27 03:29 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257269
|
4.3 |
MEDIUM
Network
|
apolloconfig
|
apollo
|
Apollo is a configuration management system. A vulnerability exists in the synchronization configuration feature that allows users to craft specific requests to bypass permission checks. This exploit…
|
NVD-CWE-Other
|
CVE-2024-43397
|
2024-08-27 03:28 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257270
|
4.3 |
MEDIUM
Network
|
umbraco
|
umbraco_cms
|
Umbraco CMS is an ASP.NET CMS. An authenticated user can access a few unintended endpoints. This issue is fixed in 14.1.2.
|
NVD-CWE-Other
|
CVE-2024-43377
|
2024-08-27 03:26 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|