|
308571
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Heap buffer overflow in Layout in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
|
CWE-787
Out-of-bounds Write
|
CVE-2024-7534
|
2024-10-15 23:35 |
2024-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308572
|
5.4 |
MEDIUM
Network
|
wpuserplus
|
userplus
|
The UserPlus plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all versions up to, and including, 2.…
|
CWE-862
Missing Authorization
|
CVE-2024-9520
|
2024-10-15 23:34 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308573
|
5.4 |
MEDIUM
Network
|
esri
|
portal_for_arcgis
|
There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.0 and below that may allow a remote, authenticated attacker to create a crafted link which when clicked could render arb…
|
CWE-79
Cross-site Scripting
|
CVE-2024-38039
|
2024-10-15 23:34 |
2024-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308574
|
6.1 |
MEDIUM
Network
|
esri
|
portal_for_arcgis
|
There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and 10.9.1 that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary …
|
CWE-601
Open Redirect
|
CVE-2024-38037
|
2024-10-15 23:34 |
2024-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308575
|
5.4 |
MEDIUM
Network
|
esri
|
portal_for_arcgis
|
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1, 10.8.1 and 10.7.1 which may allow a remote, unauthenticated attacker to create a crafted link which when clicked coul…
|
CWE-79
Cross-site Scripting
|
CVE-2024-38036
|
2024-10-15 23:34 |
2024-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308576
|
4.8 |
MEDIUM
Network
|
esri
|
portal_for_arcgis
|
There is a reflected cross site scripting in Esri Portal for ArcGIS 11.1 and below on Windows and Linux x64 allows a remote authenticated attacker with administrative access to supply a crafted strin…
|
CWE-79
Cross-site Scripting
|
CVE-2024-25707
|
2024-10-15 23:34 |
2024-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308577
|
6.1 |
MEDIUM
Network
|
esri
|
portal_for_arcgis
|
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1, 10.8.1 and 10.7.1 which may allow a remote, unauthenticated attacker to create a crafted link which when clicked coul…
|
CWE-79
Cross-site Scripting
|
CVE-2024-38038
|
2024-10-15 23:33 |
2024-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308578
|
4.3 |
MEDIUM
Network
|
andreamarinucci
|
notification_for_telegram
|
The Notification for Telegram plugin for WordPress is vulnerable to unauthorized test message sending due to a missing capability check on the 'nftb_test_action' function in versions up to, and inclu…
|
CWE-862
Missing Authorization
|
CVE-2024-9685
|
2024-10-15 23:30 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308579
|
7.3 |
HIGH
Network
|
happyplugins
|
shortcodes_anywhere
|
The Shortcodes AnyWhere plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.0.1. This is due to the software allowing users to execute an actio…
|
CWE-94
Code Injection
|
CVE-2024-9581
|
2024-10-15 23:28 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308580
|
8.8 |
HIGH
Network
|
lagunaisw
|
wp_users_masquerade
|
The WP Users Masquerade plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.0. This is due to incorrect authentication and capability checking in the 'aj…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2024-9522
|
2024-10-15 23:27 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|