2081
|
5.4 |
MEDIUM
Network
|
funnelkit
|
funnel_builder
|
The FunnelKit Funnel Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'allow_iframe_tag_in_post' function which uses the 'wp_kses_allowed_html' filter to globally…
|
CWE-79
Cross-site Scripting
|
CVE-2024-1056
|
2024-09-20 07:06 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2082
|
9.8 |
CRITICAL
Network
geeeeeeeek
|
dingfanzu
|
A vulnerability was found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. It has been rated as critical. Affected by this issue is some unknown functionality of the file /ajax/chpwd.…
|
CWE-89
SQL Injection
|
CVE-2024-8302
|
2024-09-20 06:55 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2083
|
9.8 |
CRITICAL
Network
stylemixthemes
|
cost_calculator_builder
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Cost Calculator Builder allows SQL Injection.This issue affects Cost Calculator Bu…
|
CWE-89
SQL Injection
|
CVE-2024-43144
|
2024-09-20 06:47 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2084
|
9.8 |
CRITICAL
Network
templateinvaders
|
ti_woocommerce_wishlist
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TemplateInvaders TI WooCommerce Wishlist allows SQL Injection.This issue affects TI WooCommerce W…
|
CWE-89
SQL Injection
|
CVE-2024-43917
|
2024-09-20 06:46 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2085
|
9.8 |
CRITICAL
Network
nitropack
|
nitropack
|
Improper Control of Generation of Code ('Code Injection') vulnerability in NitroPack Inc. NitroPack allows Code Injection.This issue affects NitroPack: from n/a through 1.16.7.
|
CWE-94
Code Injection
|
CVE-2024-43922
|
2024-09-20 06:44 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2086
|
8.8 |
HIGH
Adjacent
|
dlink
|
covr-x1870_firmware dir-x4860_firmware
|
Certain models of D-Link wireless routers contain hidden functionality. By sending specific packets to the web service, the attacker can forcibly enable the telnet service and log in using hard-coded…
|
CWE-912
Hidden Functionality
|
CVE-2024-45696
|
2024-09-20 06:42 |
2024-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2087
|
9.8 |
CRITICAL
Network
dlink
|
dir-x4860_firmware
|
Certain models of D-Link wireless routers do not properly validate user input in the telnet service, allowing unauthenticated remote attackers to use hard-coded credentials to log into telnet and inj…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2024-45698
|
2024-09-20 06:40 |
2024-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2088
|
9.8 |
CRITICAL
Network
dlink
|
dir-x4860_firmware
|
Certain models of D-Link wireless routers have a hidden functionality where the telnet service is enabled when the WAN port is plugged in. Unauthorized remote attackers can log in and execute OS comm…
|
CWE-912
Hidden Functionality
|
CVE-2024-45697
|
2024-09-20 06:40 |
2024-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2089
|
9.8 |
CRITICAL
Network
prixan
|
prixanconnect
|
Prixan prixanconnect up to v1.62 was discovered to contain a SQL injection vulnerability via the component CartsGuruCatalogModuleFrontController::importProducts().
|
CWE-89
SQL Injection
|
CVE-2023-40920
|
2024-09-20 06:35 |
2023-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2090
|
6.7 |
MEDIUM
Local
|
watchguard
|
epp_firmware edr_firmware epdr_firmware panda_ad360_firmware
|
An issue was discovered in WatchGuard EPDR 8.0.21.0002. It is possible to bypass the defensive capabilities by adding a registry key as SYSTEM.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2023-26237
|
2024-09-20 06:35 |
2023-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|