|
307451
|
5.4 |
MEDIUM
Network
|
vowelweb
|
ibtana
|
The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ attribute within the 'wp:ive/ive-productscarousel' Gutenberg block in all vers…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8282
|
2024-10-8 05:11 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307452
|
6.5 |
MEDIUM
Adjacent
|
gotenna
|
atak_plugin
|
In the goTenna Pro ATAK Plugin application, the encryption keys are
stored along with a static IV on the device. This allows for complete
decryption of keys stored on the device. This allows an att…
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2024-43694
|
2024-10-8 04:40 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307453
|
- |
|
-
|
-
|
Syrotech SY-GOPON-8OLT-L3 v1.6.0_240629 was discovered to contain an authenticated command injection vulnerability.
|
-
|
CVE-2024-46658
|
2024-10-8 04:37 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307454
|
- |
|
-
|
-
|
Several CGI endpoints are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POST requests to the strcpy function on DrayTek Vigor…
|
-
|
CVE-2024-41590
|
2024-10-8 04:37 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307455
|
- |
|
-
|
-
|
The CGI endpoints v2x00.cgi and cgiwcg.cgi of DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters pa…
|
-
|
CVE-2024-41588
|
2024-10-8 04:37 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307456
|
- |
|
-
|
-
|
DrayTek Vigor3910 devices through 4.3.2.6 are affected by an OS command injection vulnerability that allows an attacker to leverage the recvCmd binary to escape from the emulated instance and inject …
|
-
|
CVE-2024-41585
|
2024-10-8 04:37 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307457
|
- |
|
-
|
-
|
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthenticated attacker to conduct an unauthorized access attack due to inadequate acc…
|
-
|
CVE-2024-42514
|
2024-10-8 04:37 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307458
|
5.4 |
MEDIUM
Network
|
connekthq
|
ajax_load_more
|
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_label’ parameter in all versions up to, and including, 7.1.2 due to in…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8505
|
2024-10-8 04:26 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307459
|
6.1 |
MEDIUM
Network
|
goldplugins
|
custom_banners
|
The Custom Banners plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8799
|
2024-10-8 04:22 |
2024-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307460
|
8.8 |
HIGH
Network
|
plugingarden
|
wp_easy_gallery
|
The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘key’ parameter in all versions up to, and including, 4.8.5 due to insufficient e…
|
CWE-89
SQL Injection
|
CVE-2024-9018
|
2024-10-8 04:20 |
2024-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|