|
309641
|
7.8 |
HIGH
Local
|
proges
|
thermoscan_ip
|
A “CWE-732: Incorrect Permission Assignment for Critical Resource” in the ThermoscanIP installation folder allows a local attacker to perform a Local Privilege Escalation.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2024-31202
|
2024-10-1 00:15 |
2024-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309642
|
5.4 |
MEDIUM
Network
|
anwp
|
football_leagues
|
The AnWP Football Leagues plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.16.7 due to insufficient input sanitization an…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8917
|
2024-09-30 23:30 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309643
|
4.3 |
MEDIUM
Network
|
wedevs
|
happy_addons_for_elementor
|
The Happy Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.2 via the Content Switcher widget. This makes it possibl…
|
NVD-CWE-noinfo
|
CVE-2024-8801
|
2024-09-30 23:23 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309644
|
7.5 |
HIGH
Network
|
boldgrid
|
w3_total_cache
|
The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.5 via Google OAuth API secrets stored in plaintext in the publicly visibl…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2023-5359
|
2024-09-30 23:19 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309645
|
6.5 |
MEDIUM
Network
|
kimhuebel
|
blogintroduction-wordpress-plugin
|
The blogintroduction-wordpress-plugin WordPress plugin through 0.3.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them vi…
|
CWE-352
Origin Validation Error
|
CVE-2024-7862
|
2024-09-30 23:15 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309646
|
8.3 |
HIGH
Network
|
proges
|
sensor_net_connect_firmware_v2
|
A “CWE-352: Cross-Site Request Forgery (CSRF)” can be exploited by remote attackers to perform state-changing operations with administrative privileges by luring authenticated victims into visiting a…
|
CWE-352
Origin Validation Error
|
CVE-2024-3083
|
2024-09-30 23:15 |
2024-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309647
|
6.1 |
MEDIUM
Network
|
proges
|
sensor_net_connect_firmware_v2
|
A “CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')” allows malicious users to permanently inject arbitrary Javascript code.
|
CWE-79
Cross-site Scripting
|
CVE-2024-31199
|
2024-09-30 23:15 |
2024-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309648
|
6.5 |
MEDIUM
Network
|
ibm
|
storage_defender
|
IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI does not validate server name during registration and unregistration operations which could expose sensitive information to an…
|
CWE-295
Improper Certificate Validation
|
CVE-2024-38324
|
2024-09-30 23:10 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309649
|
5.3 |
MEDIUM
Network
|
tinfoilsecurity
|
devise-two-factor
|
Under the default configuration, Devise-Two-Factor versions >= 2.2.0 & < 6.0.0 generate TOTP shared secrets that are 120 bits instead of the 128-bit minimum defined by RFC 4226. Using a shared secret…
|
CWE-331
Insufficient Entropy
|
CVE-2024-8796
|
2024-09-30 23:10 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309650
|
6.5 |
MEDIUM
Network
|
rubayathasan
|
infolinks_ad_wrap
|
The infolinks Ad Wrap WordPress plugin through 1.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
|
CWE-352
Origin Validation Error
|
CVE-2024-8044
|
2024-09-30 23:03 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|