|
308661
|
5.3 |
MEDIUM
Network
|
getastra
|
wp_hardening
|
The WP Hardening – Fix Your WordPress Security plugin for WordPress is vulnerable to Security Feature Bypass in all versions up to, and including, 1.2.6. This is due to use of an incorrect regular ex…
|
CWE-697
Incorrect Comparison
|
CVE-2024-6641
|
2024-09-26 04:07 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308662
|
6.1 |
MEDIUM
Network
|
svelte
|
svelte
|
svelte performance oriented web framework. A potential mXSS vulnerability exists in Svelte for versions up to but not including 4.2.19. Svelte improperly escapes HTML on server-side rendering. The as…
|
CWE-79
Cross-site Scripting
|
CVE-2024-45047
|
2024-09-26 04:06 |
2024-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308663
|
6.1 |
MEDIUM
Network
|
elizsoftware
|
panel
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Eliz Software Panel allows Reflected XSS.This issue affects Panel: before v2.3.24.
|
CWE-79
Cross-site Scripting
|
CVE-2024-6877
|
2024-09-26 03:57 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308664
|
9.8 |
CRITICAL
Network
|
elizsoftware
|
panel
|
Plaintext Storage of a Password vulnerability in Eliz Software Panel allows : Use of Known Domain Credentials.This issue affects Panel: before v2.3.24.
|
CWE-256
Plaintext Storage of a Password
|
CVE-2024-5960
|
2024-09-26 03:55 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308665
|
5.3 |
MEDIUM
Network
|
felixmoira
|
limit_login_attempts_plus
|
The Limit Login Attempts Plus plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.1.0. This is due to insufficient restrictions on where the IP Address infor…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2022-4533
|
2024-09-26 03:53 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308666
|
6.1 |
MEDIUM
Network
|
ibericode
|
mailchimp
|
The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email' parameter when a placeholder such as {email} is used for the field in versions …
|
CWE-79
Cross-site Scripting
|
CVE-2024-8850
|
2024-09-26 03:49 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308667
|
8.8 |
HIGH
Network
|
jeanmarc77
|
123solar
|
A vulnerability was found in jeanmarc77 123solar 1.8.4.5. It has been rated as critical. Affected by this issue is some unknown functionality of the file config/config_invt1.php. The manipulation of …
|
CWE-94
Code Injection
|
CVE-2024-9006
|
2024-09-26 03:44 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308668
|
5.4 |
MEDIUM
Network
|
jeanmarc77
|
123solar
|
A vulnerability classified as problematic has been found in jeanmarc77 123solar 1.8.4.5. This affects an unknown part of the file /detailed.php. The manipulation of the argument date1 leads to cross …
|
CWE-79
Cross-site Scripting
|
CVE-2024-9007
|
2024-09-26 03:40 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308669
|
5.3 |
MEDIUM
Network
|
overleaf
|
overleaf
|
Overleaf is a web-based collaborative LaTeX editor. Overleaf Community Edition and Server Pro prior to version 5.0.7 (or 4.2.7 for the 4.x series) contain a vulnerability that allows an arbitrary lan…
|
CWE-74
Injection
|
CVE-2024-45312
|
2024-09-26 03:37 |
2024-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308670
|
6.0 |
MEDIUM
Network
|
fortinet
|
forticlient_endpoint_management_server
|
A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiClientEMS versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.13, 6.4.0 through 6.4.9, 6.2.0 through 6.2.…
|
CWE-22
Path Traversal
|
CVE-2024-21753
|
2024-09-26 03:36 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|