71
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in Codebard CodeBard Help Desk allows Cross Site Request Forgery.This issue affects CodeBard Help Desk: from n/a through 1.1.1.
New
|
CWE-352
Origin Validation Error
|
CVE-2024-56222
|
2024-12-31 19:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
72
|
- |
|
-
|
-
|
Incorrect Privilege Assignment vulnerability in SSL Wireless SSL Wireless SMS Notification allows Privilege Escalation.This issue affects SSL Wireless SMS Notification: from n/a through 3.5.0.
New
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2024-56220
|
2024-12-31 19:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
73
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in AuRise Creative, SevenSpark Contact Form 7 Dynamic Text Extension allows Cross Site Request Forgery.This issue affects Contact Form 7 Dynamic Text E…
New
|
CWE-352
Origin Validation Error
|
CVE-2024-56218
|
2024-12-31 19:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
74
|
- |
|
-
|
-
|
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themify Themify Builder allows PHP Local File Inclusion.This issue affects The…
New
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2024-56216
|
2024-12-31 19:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
75
|
- |
|
-
|
-
|
Path Traversal: '.../...//' vulnerability in DeluxeThemes Userpro allows Path Traversal.This issue affects Userpro: from n/a through 5.1.9.
New
|
CWE-35
Path Traversal: '.../...//'
|
CVE-2024-56214
|
2024-12-31 19:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
76
|
- |
|
-
|
-
|
Path Traversal: '.../...//' vulnerability in Themewinter Eventin allows Path Traversal.This issue affects Eventin: from n/a through 4.0.7.
New
|
CWE-35
Path Traversal: '.../...//'
|
CVE-2024-56213
|
2024-12-31 19:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
77
|
- |
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DeluxeThemes Userpro.This issue affects Userpro: from n/a through 5.1.9.
New
|
CWE-89
SQL Injection
|
CVE-2024-56212
|
2024-12-31 19:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
78
|
- |
|
-
|
-
|
Missing Authorization vulnerability in DeluxeThemes Userpro.This issue affects Userpro: from n/a through 5.1.9.
New
|
CWE-862
Missing Authorization
|
CVE-2024-56211
|
2024-12-31 19:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
79
|
- |
|
-
|
-
|
Protection Mechanism Failure in bootloader prior to SMR Oct-2024 Release 1 allows physical attackers to reset lockscreen failure count by hardware fault injection. User interaction is required for tr…
New
|
-
|
CVE-2024-49422
|
2024-12-31 18:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
80
|
- |
|
-
|
-
|
The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install and activate arbitrary Hunk Companion WordPress plu…
New
|
-
|
CVE-2024-11972
|
2024-12-31 15:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|