|
308441
|
5.4 |
MEDIUM
Network
|
themeisle
|
orbit_fox
|
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.10.36 due to insufficient input sanitization …
|
CWE-79
Cross-site Scripting
|
CVE-2024-7778
|
2024-09-27 07:22 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308442
|
6.5 |
MEDIUM
Network
|
mediajedi
|
user_private_files
|
The User Private Files – WordPress File Sharing Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.0 via the 'dpk_upvf_update_doc'…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-7848
|
2024-09-27 07:12 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308443
|
5.3 |
MEDIUM
Network
|
maxfoundry
|
maxbuttons
|
The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 9.7.8. This makes it possible for unauthenticated attackers to …
|
NVD-CWE-noinfo
|
CVE-2024-6499
|
2024-09-27 07:07 |
2024-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308444
|
5.4 |
MEDIUM
Network
|
pixelgrade
|
nova_blocks
|
The Nova Blocks by Pixelgrade plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' attribute of the 'wp:separator' Gutenberg block in all versions up to, and including, 2…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8241
|
2024-09-27 07:03 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308445
|
4.3 |
MEDIUM
Network
|
themeum
|
tutor_lms
|
The Tutor LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.4. This is due to missing or incorrect nonce validation on the 'addon_enable_disab…
|
CWE-352
Origin Validation Error
|
CVE-2023-2919
|
2024-09-27 06:59 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308446
|
8.8 |
HIGH
Network
|
tribulant
|
newsletters
|
The Newsletters plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.9.9.2. This is due to the plugin not restricting what user meta can be updated as sc…
|
NVD-CWE-noinfo
|
CVE-2024-8247
|
2024-09-27 06:49 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308447
|
4.3 |
MEDIUM
Network
|
jetplugs
|
revision_manager_tmc
|
The Revision Manager TMC plugin for WordPress is vulnerable to unauthorized arbitrary email sending due to a missing capability check on the _a_ajaxQuickEmailTestCallback() function in all versions u…
|
CWE-862
Missing Authorization
|
CVE-2024-7622
|
2024-09-27 06:42 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308448
|
7.5 |
HIGH
Network
|
openplcproject
|
openplc_v3_firmware
|
Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a36d95b73e7b8722d0edb8b9c5bb56a. A specially crafted EtherNet…
|
CWE-704
Incorrect Type Conversion or Cast
|
CVE-2024-39589
|
2024-09-27 06:36 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308449
|
7.5 |
HIGH
Network
|
openplcproject
|
openplc_v3_firmware
|
Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a36d95b73e7b8722d0edb8b9c5bb56a. A specially crafted EtherNet…
|
CWE-704
Incorrect Type Conversion or Cast
|
CVE-2024-39590
|
2024-09-27 06:02 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308450
|
7.5 |
HIGH
Network
|
openplcproject
|
openplc_v3_firmware
|
An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f71b4543298d77007b88. A specially crafted network request can…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-36981
|
2024-09-27 05:55 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|