801
|
5.5 |
MEDIUM
Local
|
silabs
|
gecko_software_development_kit
|
The initialization vector (IV) used by the secure engine (SE) for encrypting data stored in the SE flash memory is uninitialized.
|
CWE-908
Use of Uninitialized Resource
|
CVE-2023-2747
|
2024-09-28 02:15 |
2023-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
802
|
8.2 |
HIGH
Network
czim
|
file-handling
|
The czim/file-handling package before 1.5.0 and 2.x before 2.3.0 (used with PHP Composer) does not properly validate URLs within makeFromUrl and makeFromAny, leading to SSRF, and to directory travers…
|
CWE-22 CWE-918
Path Traversal Server-Side Request Forgery (SSRF)
|
CVE-2024-47049
|
2024-09-28 02:09 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
803
|
7.5 |
HIGH
Network
in2code
|
powermail
|
An issue was discovered in the powermail extension through 12.4.0 for TYPO3. It fails to validate the mail parameter of the createAction, resulting in Insecure Direct Object Reference (IDOR) in some …
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-47047
|
2024-09-28 02:03 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
804
|
6.1 |
MEDIUM
Network
|
yithemes
|
yith_custom_login
|
The YITH Custom Login plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8665
|
2024-09-28 01:59 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
805
|
6.1 |
MEDIUM
Network
|
moc
|
review_ratings
|
The Review Ratings WordPress plugin through 1.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Store…
|
CWE-352
Origin Validation Error
|
CVE-2024-8052
|
2024-09-28 01:55 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
806
|
5.5 |
MEDIUM
Local
|
ibm
|
cognos_analytics cognos_analytics_reports
|
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Reports for iOS 11.0.0.7 could allow a local attacker to obtain sensitive informa…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2024-40703
|
2024-09-28 01:49 |
2024-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
807
|
5.4 |
MEDIUM
Network
|
artembovkun
|
slider_comparison_image_before_and_after
|
The Slider comparison image before and after plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [sciba] shortcode in all versions up to, and including, 0.8.3 due to in…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8543
|
2024-09-28 01:46 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
808
|
5.3 |
MEDIUM
Network
lilmonkee
|
woocommerce_multiple_free_gift
|
The WooCommerce Multiple Free Gift plugin for WordPress is vulnerable to gift manipulation in all versions up to, and including, 1.2.3. This is due to plugin not enforcing server-side checks on the p…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2022-3459
|
2024-09-28 01:43 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
809
|
6.1 |
MEDIUM
Network
|
iredmail
|
iredadmin
|
iRedAdmin before 2.6 allows XSS, e.g., via order_name.
|
CWE-79
Cross-site Scripting
|
CVE-2024-47227
|
2024-09-28 01:37 |
2024-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
810
|
- |
|
-
|
-
|
An access control issue in the CheckVip function in UserController.java of IceCMS v3.4.7 and before allows unauthenticated attackers to access and returns all user information, including passwords
|
-
|
CVE-2024-46609
|
2024-09-28 01:35 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|