|
308311
|
7.3 |
HIGH
Network
|
pluginus
|
wordpress_meta_data_and_taxonomies_filter
|
The The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.3.3.3. This is due to the software allowing …
|
CWE-94
Code Injection
|
CVE-2024-8623
|
2024-09-27 01:46 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308312
|
8.8 |
HIGH
Network
|
ba-booking
|
ba_book_everything
|
The BA Book Everything plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.20. This is due to missing or incorrect nonce validation on the my_ac…
|
CWE-352
Origin Validation Error
|
CVE-2024-8795
|
2024-09-27 01:46 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308313
|
9.9 |
CRITICAL
Network
|
pluginus
|
wordpress_meta_data_and_taxonomies_filter
|
The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to SQL Injection via the 'meta_key' attribute of the 'mdf_select_title' shortcode in all versions up to, and including, 1…
|
CWE-89
SQL Injection
|
CVE-2024-8624
|
2024-09-27 01:45 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308314
|
5.4 |
MEDIUM
Network
|
wpcodeus
|
advanced_sermons
|
The Advanced Sermons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘sermon_video_embed’ parameter in all versions up to, and including, 3.3 due to insufficient input sanit…
|
CWE-79
Cross-site Scripting
|
CVE-2024-7599
|
2024-09-27 01:45 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308315
|
5.4 |
MEDIUM
Network
|
mailoptin
|
mailoptin
|
The Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'post-meta' shortcode in all ve…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8628
|
2024-09-27 01:42 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308316
|
9.1 |
CRITICAL
Network
|
exthemes
|
wooevents
|
The WooEvents - Calendar and Event Booking plugin for WordPress is vulnerable to arbitrary file overwrite due to insufficient file path validation in the inc/barcode.php file in all versions up to, a…
|
CWE-22
Path Traversal
|
CVE-2024-8671
|
2024-09-27 01:38 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308317
|
5.4 |
MEDIUM
Network
|
wp-brandtheme
|
preloader_plus
|
The Preloader Plus – WordPress Loading Screen Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.2.1 due to insuffic…
|
CWE-79
Cross-site Scripting
|
CVE-2024-6849
|
2024-09-27 01:36 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308318
|
- |
|
-
|
-
|
Directory Traversal vulnerability in Centro de Tecnologia da Informaco Renato Archer InVesalius3 v3.1.99995 allows attackers to write arbitrary files unto the system via a crafted .inv3 file.
|
-
|
CVE-2024-44825
|
2024-09-27 01:35 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308319
|
9.8 |
CRITICAL
Network
|
code-projects
|
student_record_system
|
A vulnerability was found in code-projects Student Record System 1.0. It has been classified as critical. Affected is an unknown function of the file /pincode-verification.php. The manipulation of th…
|
CWE-89
SQL Injection
|
CVE-2024-9080
|
2024-09-27 01:32 |
2024-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308320
|
9.8 |
CRITICAL
Network
|
code-projects
|
student_record_system
|
A vulnerability was found in code-projects Student Record System 1.0 and classified as critical. This issue affects some unknown processing of the file /marks.php. The manipulation of the argument co…
|
CWE-89
SQL Injection
|
CVE-2024-9079
|
2024-09-27 01:32 |
2024-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|