|
310101
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The SEUR Oficial plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'change_service' parameter in all versions up to, and including, 2.2.11 due to insufficient input sanitiz…
|
CWE-80
Basic XSS
|
CVE-2024-9438
|
2024-10-29 18:15 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310102
|
- |
|
-
|
-
|
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1 and 9.5.x <= 9.5.9 fail to prevent detailed error messages from being displayed in Playbooks which allows an attacker to generate a large respon…
|
-
|
CVE-2024-47401
|
2024-10-29 18:15 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310103
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Post Status Notifier Lite and Premium plugins for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in all versions up to, and including, 1.11.6 due to insufficie…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10048
|
2024-10-29 18:15 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310104
|
- |
|
-
|
-
|
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to check that the origin of the message in an integration action matches with the original post metadata which allows an au…
|
-
|
CVE-2024-50052
|
2024-10-29 17:15 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310105
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.4 via the render function in elements/tabs/tabs.php. …
|
CWE-200
Information Exposure
|
CVE-2024-10312
|
2024-10-29 17:15 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310106
|
- |
|
-
|
-
|
Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled which allows a user to get private channel names by using cmd+K/ctrl+K.
|
-
|
CVE-2024-10241
|
2024-10-29 17:15 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310107
|
8.8 |
HIGH
Network
|
-
|
-
|
The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to unauthorized user profile modification due to missing authorization checks on the /wp-json/…
|
CWE-862
Missing Authorization
|
CVE-2024-10008
|
2024-10-29 15:15 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310108
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the question's content parameter in all versions up to, and…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10000
|
2024-10-29 15:15 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310109
|
- |
|
-
|
-
|
There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authenticated attacker could use the vulnerability to exe…
|
-
|
CVE-2024-22065
|
2024-10-29 11:15 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310110
|
- |
|
-
|
-
|
A vulnerability, which was classified as problematic, was found in LinZhaoguan pb-cms up to 2.0.1. Affected is an unknown function of the file /admin#themes of the component Theme Management Module. …
|
CWE-79
Cross-site Scripting
|
CVE-2024-10479
|
2024-10-29 11:15 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|