|
309471
|
6.4 |
MEDIUM
Local
|
amd
|
epyc_8024pn_firmware epyc_8024p_firmware epyc_8124pn_firmware epyc_8124p_firmware epyc_8224pn_firmware epyc_8224p_firmware epyc_8324pn_firmware epyc_8324p_firmware epyc_8434pn…
|
A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow
an attacker with ring0 privileges and access to the
BIOS menu or UEFI shell to modify the communications buffer potentially
resulting in arbitrar…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2023-20578
|
2024-10-3 02:35 |
2024-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309472
|
4.3 |
MEDIUM
Network
|
wpplugin
|
easy_paypal_events
|
The Easy PayPal Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to missing or incorrect nonce validation on the wpeeve…
|
CWE-352
Origin Validation Error
|
CVE-2024-8476
|
2024-10-3 02:31 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309473
|
8.8 |
HIGH
Network
|
supsystic
|
slider social_share_buttons
|
Missing Authorization vulnerability in Supsystic Slider by Supsystic, Supsystic Social Share Buttons by Supsystic.This issue affects Slider by Supsystic: from n/a through 1.8.6; Social Share Buttons …
|
CWE-862
Missing Authorization
|
CVE-2024-47330
|
2024-10-3 02:26 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309474
|
4.3 |
MEDIUM
Network
|
themehunk
|
easy_mega_menu_plugin
|
The Easy Mega Menu Plugin for WordPress – ThemeHunk plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions hooked via AJAX in all versions up…
|
CWE-862
Missing Authorization
|
CVE-2024-8434
|
2024-10-3 02:25 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309475
|
7.8 |
HIGH
Local
|
avg
|
internet_security
|
Local Privilege Escalation in AVG Internet Security v24 on Windows allows a local unprivileged user to escalate privileges to SYSTEM via COM-Hijacking.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2024-6510
|
2024-10-3 02:17 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309476
|
6.1 |
MEDIUM
Network
|
dotsquares
|
contact_form_7_math_captcha
|
The Contact Form 7 Math Captcha WordPress plugin through 2.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could …
|
CWE-79
Cross-site Scripting
|
CVE-2024-6517
|
2024-10-3 02:15 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309477
|
6.1 |
MEDIUM
Network
|
madfishdigital
|
bulk_noindex_\&_nofollow_toolkit
|
The Bulk NoIndex & NoFollow Toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up …
|
CWE-79
Cross-site Scripting
|
CVE-2024-8803
|
2024-10-3 02:15 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309478
|
2.7 |
LOW
Network
|
uncannyowl
|
uncanny_groups_for_learndash
|
The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to user group add due to a missing capability check on the /wp-json/ulgm_management/v1/add_user/ REST API endpoint in all versions …
|
CWE-862
Missing Authorization
|
CVE-2024-8350
|
2024-10-3 02:10 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309479
|
5.4 |
MEDIUM
Network
|
wangbin
|
012_ps_multi_languages
|
The 012 Ps Multi Languages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via translated titles in all versions up to, and including, 1.6 due to insufficient input sanitization and…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8723
|
2024-10-3 02:00 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309480
|
4.3 |
MEDIUM
Network
|
wpchill
|
download_monitor
|
The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enable_shop() function in all versions up to, and including, 5.0.…
|
CWE-862
Missing Authorization
|
CVE-2024-8552
|
2024-10-3 02:00 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|