931
|
4.9 |
MEDIUM
Network
|
hashicorp
|
vault
|
A Vault Enterprise Sentinel Role Governing Policy created by an operator to restrict access to resources in one namespace can be applied to requests outside in another non-descendant namespace, poten…
|
NVD-CWE-noinfo
|
CVE-2023-3775
|
2024-09-27 07:15 |
2023-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
932
|
4.9 |
MEDIUM
Network
|
hashicorp
|
vault
|
An unhandled error in Vault Enterprise's namespace creation may cause the Vault process to crash, potentially resulting in denial of service. Fixed in 1.14.1, 1.13.5, and 1.12.9.
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2023-3774
|
2024-09-27 07:15 |
2023-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
933
|
6.5 |
MEDIUM
Network
|
mediajedi
|
user_private_files
|
The User Private Files – WordPress File Sharing Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.0 via the 'dpk_upvf_update_doc'…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-7848
|
2024-09-27 07:12 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
934
|
5.3 |
MEDIUM
Network
maxfoundry
|
maxbuttons
|
The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 9.7.8. This makes it possible for unauthenticated attackers to …
|
NVD-CWE-noinfo
|
CVE-2024-6499
|
2024-09-27 07:07 |
2024-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
935
|
5.4 |
MEDIUM
Network
|
pixelgrade
|
nova_blocks
|
The Nova Blocks by Pixelgrade plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' attribute of the 'wp:separator' Gutenberg block in all versions up to, and including, 2…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8241
|
2024-09-27 07:03 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
936
|
4.3 |
MEDIUM
Network
|
themeum
|
tutor_lms
|
The Tutor LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.4. This is due to missing or incorrect nonce validation on the 'addon_enable_disab…
|
CWE-352
Origin Validation Error
|
CVE-2023-2919
|
2024-09-27 06:59 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
937
|
8.8 |
HIGH
Network
|
ultimatemember
|
forumwp
|
The ForumWP – Forum & Discussion Board Plugin plugin for WordPress is vulnerable to Privilege Escalation via Insecure Direct Object Reference in all versions up to, and including, 2.0.2 via the submi…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-8428
|
2024-09-27 06:58 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
938
|
8.8 |
HIGH
Network
|
tribulant
|
newsletters
|
The Newsletters plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.9.9.2. This is due to the plugin not restricting what user meta can be updated as sc…
|
NVD-CWE-noinfo
|
CVE-2024-8247
|
2024-09-27 06:49 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
939
|
4.3 |
MEDIUM
Network
|
jetplugs
|
revision_manager_tmc
|
The Revision Manager TMC plugin for WordPress is vulnerable to unauthorized arbitrary email sending due to a missing capability check on the _a_ajaxQuickEmailTestCallback() function in all versions u…
|
CWE-862
Missing Authorization
|
CVE-2024-7622
|
2024-09-27 06:42 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
940
|
7.5 |
HIGH
Network
openplcproject
|
openplc_v3_firmware
|
Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a36d95b73e7b8722d0edb8b9c5bb56a. A specially crafted EtherNet…
|
CWE-704
Incorrect Type Conversion or Cast
|
CVE-2024-39589
|
2024-09-27 06:36 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|