|
309311
|
4.8 |
MEDIUM
Network
|
starkdigital
|
wp_testimonial_widget
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Stark Digital WP Testimonial Widget allows Stored XSS.This issue affects WP Testimonial Wi…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43967
|
2024-09-19 02:00 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309312
|
8.8 |
HIGH
Network
|
thimpress
|
learnpress
|
Cross-Site Request Forgery (CSRF) vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.6.8.2.
|
CWE-352
Origin Validation Error
|
CVE-2024-39641
|
2024-09-19 01:57 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309313
|
8.8 |
HIGH
Network
|
themeum
|
tutor_lms
|
Cross-Site Request Forgery (CSRF) vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.7.2.
|
CWE-352
Origin Validation Error
|
CVE-2024-39645
|
2024-09-19 01:46 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309314
|
8.8 |
HIGH
Network
|
sender
|
sender
|
Cross-Site Request Forgery (CSRF) vulnerability in Sender Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce.This issue affects Sender – Newsletter, SMS and Email Marketing Autom…
|
CWE-352
Origin Validation Error
|
CVE-2024-39657
|
2024-09-19 01:25 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309315
|
8.8 |
HIGH
Network
|
10up
|
simple_local_avatars
|
Cross-Site Request Forgery (CSRF) vulnerability in 10up Simple Local Avatars.This issue affects Simple Local Avatars: from n/a through 2.7.10.
|
CWE-352
Origin Validation Error
|
CVE-2024-43116
|
2024-09-19 01:22 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309316
|
8.8 |
HIGH
Network
|
loftware
|
spectrum
|
Loftware Spectrum before 4.6 HF14 allows authenticated XXE attacks.
|
CWE-611
XXE
|
CVE-2023-37233
|
2024-09-19 01:10 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309317
|
9.8 |
CRITICAL
Network
|
loftware
|
spectrum
|
Loftware Spectrum through 4.6 has unprotected JMX Registry.
|
NVD-CWE-noinfo
|
CVE-2023-37234
|
2024-09-19 01:05 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309318
|
7.5 |
HIGH
Network
|
loftware
|
spectrum
|
Loftware Spectrum through 4.6 exposes Sensitive Information (Logs) to an Unauthorized Actor.
|
NVD-CWE-noinfo
|
CVE-2023-37232
|
2024-09-19 00:55 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309319
|
8.8 |
HIGH
Network
|
inspireui
|
mstore_api
|
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_user_profile() function i…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-8242
|
2024-09-19 00:47 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309320
|
9.1 |
CRITICAL
Network
|
siemens
|
simatic_rf360r_firmware simatic_rf1170r_firmware simatic_rf1140r_firmware simatic_reader_rf685r_fcc_firmware simatic_reader_rf685r_etsi_firmware simatic_reader_rf685r_cmiit_firmware
|
A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC Reader RF…
|
NVD-CWE-noinfo
|
CVE-2024-37995
|
2024-09-19 00:37 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|