1101
|
6.6 |
MEDIUM
Local
|
linux fedoraproject redhat
|
linux_kernel fedora enterprise_linux
|
A flaw was found in the Netfilter subsystem in the Linux kernel. The issue is in the nft_byteorder_eval() function, where the code iterates through a loop and writes to the `dst` array. On each itera…
|
NVD-CWE-Other
|
CVE-2024-0607
|
2024-09-27 22:15 |
2024-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1102
|
8.8 |
HIGH
Network
|
wpmarketingrobot
|
woocommerce_google_feed_manager
|
The WooCommerce Google Feed Manager plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'wppfm_removeFeedFile' function in all versions up to, and…
|
CWE-862
Missing Authorization
|
CVE-2024-7258
|
2024-09-27 22:05 |
2024-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1103
|
4.3 |
MEDIUM
Network
|
webba-booking
|
webba_booking
|
The Appointment & Event Booking Calendar Plugin – Webba Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_appearance() func…
|
CWE-862
Missing Authorization
|
CVE-2024-8432
|
2024-09-27 21:58 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1104
|
6.1 |
MEDIUM
Network
|
fatcatapps
|
pixel_cat
|
The Pixel Cat – Conversion Pixel Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions u…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8544
|
2024-09-27 21:57 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1105
|
5.4 |
MEDIUM
Network
|
ggnome
|
garden_gnome_package
|
The Garden Gnome Package plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ggpkg shortcode in all versions up to, and including, 2.2.9 due to insufficient input sanit…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8657
|
2024-09-27 21:56 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1106
|
6.1 |
MEDIUM
Network
|
ibericode
|
koko_analytics
|
The Koko Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8662
|
2024-09-27 21:54 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1107
|
4.3 |
MEDIUM
Network
|
themify
|
themify_builder
|
The Themify Builder plugin for WordPress is vulnerable to unauthorized post duplication due to missing checks on the duplicate_page_ajaxify function in all versions up to, and including, 7.6.1. This …
|
CWE-863
Incorrect Authorization
|
CVE-2024-7836
|
2024-09-27 21:53 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1108
|
7.2 |
HIGH
Network
|
presstigers
|
simple_job_board
|
The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.3 via deserialization of untrusted input when editing job applications. This…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-7351
|
2024-09-27 21:48 |
2024-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1109
|
8.8 |
HIGH
Network
|
radiustheme
|
classified_listing
|
Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme Classified Listing plugin <= 2.4.5 versions.
|
CWE-352
Origin Validation Error
|
CVE-2023-37387
|
2024-09-27 21:41 |
2023-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1110
|
6.1 |
MEDIUM
Network
|
radiustheme
|
classified_listing
|
The Classified Listing Pro WordPress plugin before 2.0.20 does not escape a generated URL before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
|
CWE-79
Cross-site Scripting
|
CVE-2022-2655
|
2024-09-27 21:41 |
2022-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|