2521
|
8.1 |
HIGH
Network
|
wpwebelite
|
woocommerce_-_social_login
|
The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.7.7. This is due to insufficient verification on the user being retu…
|
NVD-CWE-noinfo
|
CVE-2024-10114
|
2024-11-8 02:04 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2522
|
5.5 |
MEDIUM
Local
|
huawei
|
harmonyos
|
Vulnerability of parameter type not being verified in the WantAgent module
Impact: Successful exploitation of this vulnerability may affect availability.
|
NVD-CWE-noinfo
|
CVE-2024-51512
|
2024-11-8 02:03 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2523
|
5.5 |
MEDIUM
Local
|
huawei
|
harmonyos
|
Vulnerability of parameter type not being verified in the WantAgent module
Impact: Successful exploitation of this vulnerability may affect availability.
|
NVD-CWE-noinfo
|
CVE-2024-51511
|
2024-11-8 02:03 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2524
|
5.5 |
MEDIUM
Local
|
huawei
|
harmonyos emui
|
Out-of-bounds access vulnerability in the logo module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
|
CWE-787
Out-of-bounds Write
|
CVE-2024-51510
|
2024-11-8 02:03 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2525
|
8.8 |
HIGH
Network
|
seopress
|
seopress
|
Missing Authorization vulnerability in The SEO Guys at SEOPress SEOPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SEOPress: from n/a through 8.1.1.
|
CWE-862
Missing Authorization
|
CVE-2024-50456
|
2024-11-8 02:02 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2526
|
8.8 |
HIGH
Network
|
seopress
|
seopress
|
Missing Authorization vulnerability in The SEO Guys at SEOPress SEOPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SEOPress: from n/a through 8.1.1.
|
CWE-862
Missing Authorization
|
CVE-2024-50455
|
2024-11-8 02:01 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2527
|
9.8 |
CRITICAL
Network
odude
|
crypto_tool
|
The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.15. This is due a to limited arbitrary method call to 'crypto_connect_ajax_process::log_in' …
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2024-9989
|
2024-11-8 02:00 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2528
|
9.8 |
CRITICAL
Network
odude
|
crypto_tool
|
The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.15. This is due to missing validation on the user being supplied in the 'crypto_connect_ajax…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2024-9988
|
2024-11-8 02:00 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2529
|
- |
|
-
|
-
|
NATO NCI ANET 3.4.1 mishandles report ownership. A user can create a report and, despite the restrictions imposed by the UI, change the author of that report to an arbitrary user (without their conse…
|
-
|
CVE-2024-38446
|
2024-11-8 01:35 |
2024-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2530
|
- |
|
-
|
-
|
Insecure permissions in the component /api/admin/user of 14Finger v1.1 allows attackers to access all user information via a crafted GET request.
|
-
|
CVE-2024-37767
|
2024-11-8 01:35 |
2024-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|