521
|
- |
|
-
|
-
|
A Session Fixation vulnerability exists in chatwoot/chatwoot versions prior to 2.4.0. The application does not invalidate existing sessions on other devices when a user changes their password, allowi…
New
|
CWE-384
Session Fixation
|
CVE-2021-3740
|
2024-11-15 22:58 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
522
|
8.0 |
HIGH
Network
|
-
|
-
|
The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, …
New
|
CWE-200
Information Exposure
|
CVE-2024-8979
|
2024-11-15 22:58 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
523
|
5.7 |
MEDIUM
Network
|
-
|
-
|
The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, …
New
|
-
|
CVE-2024-8978
|
2024-11-15 22:58 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
524
|
7.5 |
HIGH
Network
|
-
|
-
|
The External Database Based Actions plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.1. This is due to a missing capability check in the 'edba_admin_han…
New
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2024-10311
|
2024-11-15 22:58 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
525
|
- |
|
-
|
-
|
Apache Airflow versions before 2.10.3 contain a vulnerability that could expose sensitive configuration variables in task logs. This vulnerability allows DAG authors to unintentionally or intentional…
New
|
-
|
CVE-2024-45784
|
2024-11-15 22:58 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
526
|
- |
|
-
|
-
|
The Secure Custom Fields WordPress plugin before 6.3.9, Secure Custom Fields WordPress plugin before 6.3.6.3, Advanced Custom Fields Pro WordPress plugin before 6.3.9 does not prevent users from runn…
New
|
-
|
CVE-2024-9529
|
2024-11-15 22:58 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
527
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘nomore_items_text…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-8961
|
2024-11-15 22:58 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
528
|
- |
|
-
|
-
|
The Hide My WP Ghost – Security & Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL in all versions up to, and including, 5.3.01 due to insufficient input sani…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-10825
|
2024-11-15 22:58 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
529
|
- |
|
-
|
-
|
The Jobs for WordPress plugin before 2.7.8 does not sanitise and escape some of its Job settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting att…
New
|
-
|
CVE-2024-10104
|
2024-11-15 22:58 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
530
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Yotpo: Product & Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'yotpo_user_email' and 'yotpo_user_name' parameters in all versions up …
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-9356
|
2024-11-15 22:58 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|