|
312001
|
4.3 |
MEDIUM
Network
|
sentry
|
sentry
|
Sentry is a developer-first error tracking and performance monitoring platform. An authenticated user can mute alert rules from arbitrary organizations and projects with a know rule ID. The user does…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-45606
|
2024-09-27 04:16 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312002
|
4.3 |
MEDIUM
Network
|
sentry
|
sentry
|
Sentry is a developer-first error tracking and performance monitoring platform. An authenticated user delete the user issue alert notifications for arbitrary users given a know alert ID. A patch was …
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-45605
|
2024-09-27 04:14 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312003
|
9.8 |
CRITICAL
Network
|
apexsoftcell
|
ld_geo ld_dp_back_office
|
This vulnerability exists in Apex Softcell LD Geo due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vulnerability b…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2024-47088
|
2024-09-27 04:12 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312004
|
6.5 |
MEDIUM
Network
|
apexsoftcell
|
ld_geo ld_dp_back_office
|
This vulnerability exists in the Apex Softcell LD Geo due to improper validation of the transaction token ID in the API endpoint. An authenticated remote attacker could exploit this vulnerability by …
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2024-47089
|
2024-09-27 04:09 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312005
|
5.3 |
MEDIUM
Network
|
circutor
|
q-smt_firmware
|
An attacker with no knowledge of the current users in the web application, could build a dictionary of potential users and check the server responses as it indicates whether or not the user is presen…
|
NVD-CWE-noinfo
|
CVE-2024-8891
|
2024-09-27 03:50 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312006
|
7.5 |
HIGH
Network
|
coredns.io
|
coredns
|
An issue was discovered in CoreDNS through 1.10.1. There is a vulnerability in DNS resolving software, which triggers a resolver to ignore valid responses, thus causing denial of service for normal r…
|
NVD-CWE-noinfo
|
CVE-2023-28452
|
2024-09-27 03:37 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312007
|
5.4 |
MEDIUM
Network
|
muffingroup
|
betheme
|
The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 27.5.5 due to insufficient input sanitization and output escapi…
|
CWE-79
Cross-site Scripting
|
CVE-2024-5567
|
2024-09-27 03:27 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312008
|
8.8 |
HIGH
Network
|
sirv
|
sirv
|
The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'sirv_save_prevented_sizes' function in al…
|
CWE-862
Missing Authorization
|
CVE-2024-8480
|
2024-09-27 03:13 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312009
|
8.8 |
HIGH
Network
|
bitapps
|
file_manager
|
The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'uplo…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-7770
|
2024-09-27 02:49 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312010
|
6.1 |
MEDIUM
Network
|
rocket.chat
|
rocket.chat
|
Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to DOM-based Cross-site Scripting (XSS). Attackers may be able to abuse the UpdateOTRAck method to forge a message t…
|
CWE-79
Cross-site Scripting
|
CVE-2024-46934
|
2024-09-27 02:41 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312011
|
7.5 |
HIGH
Network
|
rocket.chat
|
rocket.chat
|
Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS). Attackers who craft messages with specific characters may crash the workspace due to an …
|
NVD-CWE-noinfo
|
CVE-2024-46935
|
2024-09-27 02:39 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312012
|
5.4 |
MEDIUM
Network
|
rocket.chat
|
rocket.chat
|
Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier allows stored XSS in the description and release notes of the marketplace and private apps.
|
CWE-79
Cross-site Scripting
|
CVE-2024-47048
|
2024-09-27 02:12 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312013
|
6.1 |
MEDIUM
Network
|
xplodedthemes
|
xt_ajax_add_to_cart_for_woocommerce
|
The XT Ajax Add To Cart for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8716
|
2024-09-27 02:03 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312014
|
6.1 |
MEDIUM
Network
|
castos
|
seriously_simple_stats
|
The Seriously Simple Stats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and incl…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8738
|
2024-09-27 01:48 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312015
|
7.3 |
HIGH
Network
|
pluginus
|
wordpress_meta_data_and_taxonomies_filter
|
The The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.3.3.3. This is due to the software allowing …
|
CWE-94
Code Injection
|
CVE-2024-8623
|
2024-09-27 01:46 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312016
|
8.8 |
HIGH
Network
|
ba-booking
|
ba_book_everything
|
The BA Book Everything plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.20. This is due to missing or incorrect nonce validation on the my_ac…
|
CWE-352
Origin Validation Error
|
CVE-2024-8795
|
2024-09-27 01:46 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312017
|
9.9 |
CRITICAL
Network
|
pluginus
|
wordpress_meta_data_and_taxonomies_filter
|
The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to SQL Injection via the 'meta_key' attribute of the 'mdf_select_title' shortcode in all versions up to, and including, 1…
|
CWE-89
SQL Injection
|
CVE-2024-8624
|
2024-09-27 01:45 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312018
|
5.4 |
MEDIUM
Network
|
wpcodeus
|
advanced_sermons
|
The Advanced Sermons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘sermon_video_embed’ parameter in all versions up to, and including, 3.3 due to insufficient input sanit…
|
CWE-79
Cross-site Scripting
|
CVE-2024-7599
|
2024-09-27 01:45 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312019
|
5.4 |
MEDIUM
Network
|
mailoptin
|
mailoptin
|
The Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'post-meta' shortcode in all ve…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8628
|
2024-09-27 01:42 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312020
|
9.1 |
CRITICAL
Network
|
exthemes
|
wooevents
|
The WooEvents - Calendar and Event Booking plugin for WordPress is vulnerable to arbitrary file overwrite due to insufficient file path validation in the inc/barcode.php file in all versions up to, a…
|
CWE-22
Path Traversal
|
CVE-2024-8671
|
2024-09-27 01:38 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312021
|
5.4 |
MEDIUM
Network
|
wp-brandtheme
|
preloader_plus
|
The Preloader Plus – WordPress Loading Screen Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.2.1 due to insuffic…
|
CWE-79
Cross-site Scripting
|
CVE-2024-6849
|
2024-09-27 01:36 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312022
|
- |
-
|
-
|
-
|
Directory Traversal vulnerability in Centro de Tecnologia da Informaco Renato Archer InVesalius3 v3.1.99995 allows attackers to write arbitrary files unto the system via a crafted .inv3 file.
|
-
|
CVE-2024-44825
|
2024-09-27 01:35 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312023
|
9.8 |
CRITICAL
Network
|
code-projects
|
student_record_system
|
A vulnerability was found in code-projects Student Record System 1.0. It has been classified as critical. Affected is an unknown function of the file /pincode-verification.php. The manipulation of th…
|
CWE-89
SQL Injection
|
CVE-2024-9080
|
2024-09-27 01:32 |
2024-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312024
|
9.8 |
CRITICAL
Network
|
code-projects
|
student_record_system
|
A vulnerability was found in code-projects Student Record System 1.0 and classified as critical. This issue affects some unknown processing of the file /marks.php. The manipulation of the argument co…
|
CWE-89
SQL Injection
|
CVE-2024-9079
|
2024-09-27 01:32 |
2024-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312025
|
9.8 |
CRITICAL
Network
|
code-projects
|
student_record_system
|
A vulnerability has been found in code-projects Student Record System 1.0 and classified as critical. This vulnerability affects unknown code of the file /course.php. The manipulation of the argument…
|
CWE-89
SQL Injection
|
CVE-2024-9078
|
2024-09-27 01:31 |
2024-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312026
|
4.3 |
MEDIUM
Network
|
infiniteuploads
|
big_file_uploads
|
The Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.1.2. This is due the plugin not sanitizing …
|
CWE-22
Path Traversal
|
CVE-2024-8538
|
2024-09-27 01:28 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312027
|
9.8 |
CRITICAL
Network
|
wpcharitable
|
charitable
|
The Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.8.1.14. Thi…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-8791
|
2024-09-27 01:25 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312028
|
5.3 |
MEDIUM
Network
|
ba-booking
|
ba_book_everything
|
The BA Book Everything plugin for WordPress is vulnerable to arbitrary password reset in all versions up to, and including, 1.6.20. This is due to the reset_user_password() function not verifying a u…
|
NVD-CWE-Other
|
CVE-2024-8794
|
2024-09-27 01:23 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312029
|
6.1 |
MEDIUM
Network
|
ninjaforms
|
ninja_forms_file_uploads
|
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. RTX file) in all versions up to, and including, 3.3.16 due to insufficient …
|
CWE-79
Cross-site Scripting
|
CVE-2024-1596
|
2024-09-27 01:23 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312030
|
5.4 |
MEDIUM
Network
|
master-addons
|
master_addons
|
The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-jltma-wrapper-link element…
|
CWE-79
Cross-site Scripting
|
CVE-2024-6282
|
2024-09-27 01:19 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312031
|
- |
-
|
-
|
-
|
Mellium mellium.im/xmpp 0.0.1 through 0.21.4 allows response spoofing if the implementation uses predictable IDs because the stanza type is not checked. This is fixed in 0.22.0.
|
-
|
CVE-2024-46957
|
2024-09-27 01:15 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312032
|
8.8 |
HIGH
Network
|
buffercode
|
frontend_dashboard
|
The Frontend Dashboard plugin for WordPress is vulnerable to unauthorized code execution due to insufficient filtering on callable methods/functions via the ajax_request() function in all versions up…
|
CWE-94
Code Injection
|
CVE-2024-8268
|
2024-09-27 01:15 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312033
|
6.5 |
MEDIUM
Network
|
pinpoint
|
pinpoint_booking_system
|
The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the ‘schedule’ parameter in all versions up to, and including, 2.9.9.5.0 due to insuf…
|
CWE-89
SQL Injection
|
CVE-2024-7112
|
2024-09-27 01:12 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312034
|
7.3 |
HIGH
Network
|
ifeelweb
|
affiliate_super_assistent
|
The The Affiliate Super Assistent plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.5.3. This is due to the software allowing users to supply…
|
CWE-94
Code Injection
|
CVE-2024-8478
|
2024-09-27 00:53 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312035
|
5.3 |
MEDIUM
Network
|
metagauss
|
eventprime
|
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access to Private or Password-protected events due to missing authorization checks in all ver…
|
CWE-862
Missing Authorization
|
CVE-2024-8369
|
2024-09-27 00:43 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312036
|
8.8 |
HIGH
Network
|
elizsoftware
|
panel
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eliz Software Panel allows Command Line Execution through SQL Injection.This issue affects Panel:…
|
CWE-89
SQL Injection
|
CVE-2024-5958
|
2024-09-27 00:35 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312037
|
6.5 |
MEDIUM
Network
|
apexsoftcell
|
ld_geo ld_dp_back_office
|
This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters (cCdslClicentcode and cLdClientCode) in the API endpoint. An authenticated remote attacke…
|
NVD-CWE-Other
|
CVE-2024-47085
|
2024-09-27 00:30 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312038
|
5.4 |
MEDIUM
Network
|
code-projects
|
blood_bank_system
|
A vulnerability classified as problematic was found in code-projects Blood Bank System 1.0. This vulnerability affects unknown code of the file bbms.php. The manipulation of the argument fullname/age…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9084
|
2024-09-27 00:29 |
2024-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312039
|
6.5 |
MEDIUM
Network
|
apexsoftcell
|
ld_geo ld_dp_back_office
|
This vulnerability exists in Apex Softcell LD DP Back Office due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this v…
|
NVD-CWE-Other
|
CVE-2024-47086
|
2024-09-27 00:29 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312040
|
9.8 |
CRITICAL
Network
|
code-projects
|
restaurant_reservation_system
|
A vulnerability classified as critical has been found in code-projects Restaurant Reservation System 1.0. Affected is an unknown function of the file /filter.php. The manipulation of the argument fro…
|
CWE-89
SQL Injection
|
CVE-2024-9086
|
2024-09-27 00:26 |
2024-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312041
|
6.5 |
MEDIUM
Network
|
apexsoftcell
|
ld_geo ld_dp_back_office
|
This vulnerability exists in Apex Softcell LD Geo due to improper validation of the certain parameters (Client ID, DPID or BOID) in the API endpoint. An authenticated remote attacker could exploit th…
|
NVD-CWE-Other
|
CVE-2024-47087
|
2024-09-27 00:25 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312042
|
9.8 |
CRITICAL
Network
|
razormist
|
telecom_billing_management_system
|
A vulnerability has been found in SourceCodester Telecom Billing Management System 1.0 and classified as critical. This vulnerability affects the function login. The manipulation of the argument unam…
|
CWE-120
Classic Buffer Overflow
|
CVE-2024-9088
|
2024-09-27 00:19 |
2024-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312043
|
9.8 |
CRITICAL
Network
|
vehicle_management_project
|
vehicle_management
|
A vulnerability, which was classified as critical, was found in code-projects Vehicle Management 1.0. This affects an unknown part of the file /edit1.php. The manipulation of the argument sno leads t…
|
CWE-89
SQL Injection
|
CVE-2024-9087
|
2024-09-27 00:16 |
2024-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312044
|
5.4 |
MEDIUM
Network
|
theme-fusion
|
avada
|
The Avada | Website Builder For WordPress & eCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fusion_button shortcode in all versions up to, and including, …
|
CWE-79
Cross-site Scripting
|
CVE-2024-5628
|
2024-09-27 00:14 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312045
|
4.3 |
MEDIUM
Network
|
realestateconnected
|
easy_property_listings
|
The Easy Property Listings WordPress plugin before 3.5.4 does not have CSRF check when deleting contacts in bulk, which could allow attackers to make a logged in admin delete them via a CSRF attack
|
CWE-352
Origin Validation Error
|
CVE-2024-3163
|
2024-09-27 00:13 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312046
|
7.5 |
HIGH
Network
|
tamparongj_03
|
online_graduate_tracer_system
|
A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /tracking/admin/fetch_it.php…
|
CWE-89
SQL Injection
|
CVE-2024-7845
|
2024-09-27 00:10 |
2024-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312047
|
6.1 |
MEDIUM
Network
|
wpfactory
|
wpfactory_helper
|
The WPFactory Helper plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including,…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8656
|
2024-09-27 00:04 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312048
|
6.1 |
MEDIUM
Network
|
amcharts
|
amcharts\
|
The amCharts: Charts and Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'amcharts_javascript' parameter in all versions up to, and including, 1.4.4 due to the abili…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8622
|
2024-09-26 23:59 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312049
|
5.9 |
MEDIUM
Network
|
fortinet
|
forticlient
|
An improper certificate validation vulnerability [CWE-295] in FortiClientWindows 6.4 all versions, 7.0.0 through 7.0.7, FortiClientMac 6.4 all versions, 7.0 all versions, 7.2.0 through 7.2.4, FortiCl…
|
CWE-295
Improper Certificate Validation
|
CVE-2022-45856
|
2024-09-26 23:48 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312050
|
9.8 |
CRITICAL
Network
|
villatheme
|
woocommerce_photo_reviews
|
The WooCommerce Photo Reviews Premium plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.3.13.2. This is due to the plugin not properly validating wha…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2024-8277
|
2024-09-26 23:39 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|