1621
|
7.5 |
HIGH
Network
rocket.chat
|
rocket.chat
|
Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS). Attackers who craft messages with specific characters may crash the workspace due to an …
|
NVD-CWE-noinfo
|
CVE-2024-46935
|
2024-09-27 02:39 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1622
|
6.8 |
MEDIUM
Network
|
hashicorp
|
vault
|
HashiCorp Vault and Vault Enterprise transit secrets engine allowed authorized users to specify arbitrary nonces, even with convergent encryption disabled. The encrypt endpoint, in combination with a…
|
CWE-20
Improper Input Validation
|
CVE-2023-4680
|
2024-09-27 02:15 |
2023-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1623
|
5.4 |
MEDIUM
Network
|
rocket.chat
|
rocket.chat
|
Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier allows stored XSS in the description and release notes of the marketplace and private apps.
|
CWE-79
Cross-site Scripting
|
CVE-2024-47048
|
2024-09-27 02:12 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1624
|
6.1 |
MEDIUM
Network
|
xplodedthemes
|
xt_ajax_add_to_cart_for_woocommerce
|
The XT Ajax Add To Cart for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8716
|
2024-09-27 02:03 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1625
|
6.1 |
MEDIUM
Network
|
castos
|
seriously_simple_stats
|
The Seriously Simple Stats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and incl…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8738
|
2024-09-27 01:48 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1626
|
7.3 |
HIGH
Network
pluginus
|
wordpress_meta_data_and_taxonomies_filter
|
The The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.3.3.3. This is due to the software allowing …
|
CWE-94
Code Injection
|
CVE-2024-8623
|
2024-09-27 01:46 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1627
|
8.8 |
HIGH
Network
|
ba-booking
|
ba_book_everything
|
The BA Book Everything plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.20. This is due to missing or incorrect nonce validation on the my_ac…
|
CWE-352
Origin Validation Error
|
CVE-2024-8795
|
2024-09-27 01:46 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1628
|
9.9 |
CRITICAL
Network
|
pluginus
|
wordpress_meta_data_and_taxonomies_filter
|
The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to SQL Injection via the 'meta_key' attribute of the 'mdf_select_title' shortcode in all versions up to, and including, 1…
|
CWE-89
SQL Injection
|
CVE-2024-8624
|
2024-09-27 01:45 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1629
|
5.4 |
MEDIUM
Network
|
wpcodeus
|
advanced_sermons
|
The Advanced Sermons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘sermon_video_embed’ parameter in all versions up to, and including, 3.3 due to insufficient input sanit…
|
CWE-79
Cross-site Scripting
|
CVE-2024-7599
|
2024-09-27 01:45 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1630
|
5.4 |
MEDIUM
Network
|
mailoptin
|
mailoptin
|
The Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'post-meta' shortcode in all ve…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8628
|
2024-09-27 01:42 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|