1021
|
6.1 |
MEDIUM
Network
|
fatcatapps
|
pixel_cat
|
The Pixel Cat – Conversion Pixel Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions u…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8544
|
2024-09-27 21:57 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1022
|
5.4 |
MEDIUM
Network
|
ggnome
|
garden_gnome_package
|
The Garden Gnome Package plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ggpkg shortcode in all versions up to, and including, 2.2.9 due to insufficient input sanit…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8657
|
2024-09-27 21:56 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1023
|
6.1 |
MEDIUM
Network
|
ibericode
|
koko_analytics
|
The Koko Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8662
|
2024-09-27 21:54 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1024
|
4.3 |
MEDIUM
Network
|
themify
|
themify_builder
|
The Themify Builder plugin for WordPress is vulnerable to unauthorized post duplication due to missing checks on the duplicate_page_ajaxify function in all versions up to, and including, 7.6.1. This …
|
CWE-863
Incorrect Authorization
|
CVE-2024-7836
|
2024-09-27 21:53 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1025
|
7.2 |
HIGH
Network
|
presstigers
|
simple_job_board
|
The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.3 via deserialization of untrusted input when editing job applications. This…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-7351
|
2024-09-27 21:48 |
2024-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1026
|
8.8 |
HIGH
Network
|
radiustheme
|
classified_listing
|
Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme Classified Listing plugin <= 2.4.5 versions.
|
CWE-352
Origin Validation Error
|
CVE-2023-37387
|
2024-09-27 21:41 |
2023-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1027
|
6.1 |
MEDIUM
Network
|
radiustheme
|
classified_listing
|
The Classified Listing Pro WordPress plugin before 2.0.20 does not escape a generated URL before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
|
CWE-79
Cross-site Scripting
|
CVE-2022-2655
|
2024-09-27 21:41 |
2022-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1028
|
6.1 |
MEDIUM
Network
|
radiustheme
|
classima classima_core classified_listing_store_\&_membership classified_listing
|
The Classima WordPress theme before 2.1.11 and some of its required plugins (Classified Listing before 2.2.14, Classified Listing Pro before 2.0.20, Classified Listing Store & Membership before 1.4.2…
|
CWE-79
Cross-site Scripting
|
CVE-2022-2654
|
2024-09-27 21:41 |
2022-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1029
|
7.5 |
HIGH
Network
apache
|
inlong
|
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attac…
|
CWE-74
Injection
|
CVE-2023-43667
|
2024-09-27 21:15 |
2023-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1030
|
7.8 |
HIGH
Local
|
hitachi
|
eh-view
|
** UNSUPPORTED WHEN ASSIGNED ** Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Hitachi EH-VIEW (KeypadDesigner) allows local attackers to potentially disclos…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2023-39984
|
2024-09-27 11:15 |
2023-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|