|
312481
|
8.8 |
HIGH
Network
|
supsystic
|
slider social_share_buttons
|
Missing Authorization vulnerability in Supsystic Slider by Supsystic, Supsystic Social Share Buttons by Supsystic.This issue affects Slider by Supsystic: from n/a through 1.8.6; Social Share Buttons …
|
CWE-862
Missing Authorization
|
CVE-2024-47330
|
2024-10-3 02:26 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312482
|
4.3 |
MEDIUM
Network
|
themehunk
|
easy_mega_menu_plugin
|
The Easy Mega Menu Plugin for WordPress – ThemeHunk plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions hooked via AJAX in all versions up…
|
CWE-862
Missing Authorization
|
CVE-2024-8434
|
2024-10-3 02:25 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312483
|
7.8 |
HIGH
Local
|
avg
|
internet_security
|
Local Privilege Escalation in AVG Internet Security v24 on Windows allows a local unprivileged user to escalate privileges to SYSTEM via COM-Hijacking.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2024-6510
|
2024-10-3 02:17 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312484
|
6.1 |
MEDIUM
Network
|
dotsquares
|
contact_form_7_math_captcha
|
The Contact Form 7 Math Captcha WordPress plugin through 2.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could …
|
CWE-79
Cross-site Scripting
|
CVE-2024-6517
|
2024-10-3 02:15 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312485
|
6.1 |
MEDIUM
Network
|
madfishdigital
|
bulk_noindex_\&_nofollow_toolkit
|
The Bulk NoIndex & NoFollow Toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up …
|
CWE-79
Cross-site Scripting
|
CVE-2024-8803
|
2024-10-3 02:15 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312486
|
2.7 |
LOW
Network
|
uncannyowl
|
uncanny_groups_for_learndash
|
The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to user group add due to a missing capability check on the /wp-json/ulgm_management/v1/add_user/ REST API endpoint in all versions …
|
CWE-862
Missing Authorization
|
CVE-2024-8350
|
2024-10-3 02:10 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312487
|
5.4 |
MEDIUM
Network
|
wangbin
|
012_ps_multi_languages
|
The 012 Ps Multi Languages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via translated titles in all versions up to, and including, 1.6 due to insufficient input sanitization and…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8723
|
2024-10-3 02:00 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312488
|
4.3 |
MEDIUM
Network
|
wpchill
|
download_monitor
|
The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enable_shop() function in all versions up to, and including, 5.0.…
|
CWE-862
Missing Authorization
|
CVE-2024-8552
|
2024-10-3 02:00 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312489
|
5.4 |
MEDIUM
Network
|
zkteco
|
wdms
|
Cross Site Scripting vulnerability in ZKTeco WDMS v.5.1.3 Pro allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted script to the Emp Name parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2023-51157
|
2024-10-3 01:58 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312490
|
7.2 |
HIGH
Network
|
uncannyowl
|
uncanny_groups_for_learndash
|
The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.1.0.1. This is due to the plugin not properly restricting what user…
|
CWE-862
Missing Authorization
|
CVE-2024-8349
|
2024-10-3 01:50 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|