751
|
8.0 |
HIGH
Adjacent
|
tp-link
|
archer_c55_firmware archer_c50_v3_firmware
|
Multiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows: Archer C50 firmware versions prior to 'Archer C5…
|
CWE-78
OS Command
|
CVE-2023-31188
|
2024-09-28 06:35 |
2023-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
752
|
8.0 |
HIGH
Network
|
apache
|
airflow
|
The session fixation vulnerability allowed the authenticated user to continue accessing Airflow webserver even after the password of the user has been reset by the admin - up until the expiry of the …
|
CWE-384
Session Fixation
|
CVE-2023-40273
|
2024-09-28 06:35 |
2023-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
753
|
8.2 |
HIGH
Network
apache
|
ivy
|
Improper Restriction of XML External Entity Reference, XML Injection (aka Blind XPath Injection) vulnerability in Apache Software Foundation Apache Ivy.This issue affects any version of Apache Ivy pr…
|
CWE-91 CWE-611
Blind XPath Injection XXE
|
CVE-2022-46751
|
2024-09-28 06:35 |
2023-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
754
|
6.1 |
MEDIUM
Network
|
mm-breaking_news_project
|
mm-breaking_news
|
The MM-Breaking News WordPress plugin through 0.7.9 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8056
|
2024-09-28 06:29 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
755
|
6.1 |
MEDIUM
Network
|
mm-breaking_news_project
|
mm-breaking_news
|
The MM-Breaking News WordPress plugin through 0.7.9 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add S…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8054
|
2024-09-28 06:29 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
756
|
4.8 |
MEDIUM
Network
|
ninjateam
|
header_footer_custom_code
|
The NinjaTeam Header Footer Custom Code WordPress plugin before 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Sit…
|
CWE-79
Cross-site Scripting
|
CVE-2024-6617
|
2024-09-28 06:28 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
757
|
4.8 |
MEDIUM
Network
|
ninjateam
|
header_footer_custom_code
|
The NinjaTeam Header Footer Custom Code WordPress plugin before 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Sit…
|
CWE-79
Cross-site Scripting
|
CVE-2024-6493
|
2024-09-28 06:28 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
758
|
6.8 |
MEDIUM
Network
|
pixeljar
|
favicon_generator
|
The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not validate files to be uploaded and does not have CSRF checks, which could allow attackers to make logged in admin upload arbitrary f…
|
CWE-352
Origin Validation Error
|
CVE-2024-7863
|
2024-09-28 06:27 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
759
|
4.8 |
MEDIUM
Network
|
premio
|
my_sticky_bar
|
The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin before 2.7.3 does not validate and escape some of its settings before outputtin…
|
CWE-79
Cross-site Scripting
|
CVE-2024-7133
|
2024-09-28 06:27 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
760
|
6.5 |
MEDIUM
Network
|
pixeljar
|
favicon_generator
|
The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not have CSRF and path validation in the output_sub_admin_page_0() function, allowing attackers to make logged in admins delete arbitra…
|
CWE-352
Origin Validation Error
|
CVE-2024-7864
|
2024-09-28 06:26 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|