|
309621
|
6.1 |
MEDIUM
Network
|
ninjaforms
|
ninja_forms_file_uploads
|
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. RTX file) in all versions up to, and including, 3.3.16 due to insufficient …
|
CWE-79
Cross-site Scripting
|
CVE-2024-1596
|
2024-09-27 01:23 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309622
|
5.4 |
MEDIUM
Network
|
master-addons
|
master_addons
|
The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-jltma-wrapper-link element…
|
CWE-79
Cross-site Scripting
|
CVE-2024-6282
|
2024-09-27 01:19 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309623
|
- |
|
-
|
-
|
Mellium mellium.im/xmpp 0.0.1 through 0.21.4 allows response spoofing if the implementation uses predictable IDs because the stanza type is not checked. This is fixed in 0.22.0.
|
-
|
CVE-2024-46957
|
2024-09-27 01:15 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309624
|
8.8 |
HIGH
Network
|
buffercode
|
frontend_dashboard
|
The Frontend Dashboard plugin for WordPress is vulnerable to unauthorized code execution due to insufficient filtering on callable methods/functions via the ajax_request() function in all versions up…
|
CWE-94
Code Injection
|
CVE-2024-8268
|
2024-09-27 01:15 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309625
|
6.5 |
MEDIUM
Network
|
pinpoint
|
pinpoint_booking_system
|
The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the ‘schedule’ parameter in all versions up to, and including, 2.9.9.5.0 due to insuf…
|
CWE-89
SQL Injection
|
CVE-2024-7112
|
2024-09-27 01:12 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309626
|
7.3 |
HIGH
Network
|
ifeelweb
|
affiliate_super_assistent
|
The The Affiliate Super Assistent plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.5.3. This is due to the software allowing users to supply…
|
CWE-94
Code Injection
|
CVE-2024-8478
|
2024-09-27 00:53 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309627
|
5.3 |
MEDIUM
Network
|
metagauss
|
eventprime
|
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access to Private or Password-protected events due to missing authorization checks in all ver…
|
CWE-862
Missing Authorization
|
CVE-2024-8369
|
2024-09-27 00:43 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309628
|
8.8 |
HIGH
Network
|
elizsoftware
|
panel
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eliz Software Panel allows Command Line Execution through SQL Injection.This issue affects Panel:…
|
CWE-89
SQL Injection
|
CVE-2024-5958
|
2024-09-27 00:35 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309629
|
6.5 |
MEDIUM
Network
|
apexsoftcell
|
ld_geo ld_dp_back_office
|
This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters (cCdslClicentcode and cLdClientCode) in the API endpoint. An authenticated remote attacke…
|
NVD-CWE-Other
|
CVE-2024-47085
|
2024-09-27 00:30 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309630
|
5.4 |
MEDIUM
Network
|
code-projects
|
blood_bank_system
|
A vulnerability classified as problematic was found in code-projects Blood Bank System 1.0. This vulnerability affects unknown code of the file bbms.php. The manipulation of the argument fullname/age…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9084
|
2024-09-27 00:29 |
2024-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|