71
|
6.3 |
MEDIUM
Network
|
-
|
-
|
The The Drop Shadow Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.7.14. This is due to the software allowing users to execute an ac…
New
|
CWE-94
Code Injection
|
CVE-2024-10262
|
2024-11-16 13:15 |
2024-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
72
|
- |
|
-
|
-
|
The Steel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's btn shortcode in all versions up to, and including, 1.3.0 due to insufficient input sanitization and outpu…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-10147
|
2024-11-16 13:15 |
2024-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
73
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The PJW Mime Config plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0 due to insufficient input sanitization and output …
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-10017
|
2024-11-16 13:15 |
2024-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
74
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The ConvertCalculator for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' and 'type' parameters in all versions up to, and including, 1.1.1 due to insufficien…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-10015
|
2024-11-16 13:15 |
2024-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
75
|
5.3 |
MEDIUM
Network
-
|
-
|
The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_plugin…
New
|
CWE-862
Missing Authorization
|
CVE-2024-10861
|
2024-11-16 12:15 |
2024-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
76
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Popularis Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.7 via the 'elementor-template' shortcode due to insufficient restrictions on w…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-10795
|
2024-11-16 12:15 |
2024-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
77
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capability check on the sla_clear_user_cache function in all versions up to, and inclu…
New
|
CWE-862
Missing Authorization
|
CVE-2024-10786
|
2024-11-16 12:15 |
2024-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
78
|
5.5 |
MEDIUM
Local
|
adobe
|
indesign
|
InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerabi…
Update
|
CWE-125
Out-of-bounds Read
|
CVE-2024-49510
|
2024-11-16 09:35 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
79
|
7.8 |
HIGH
Local
|
adobe
|
indesign
|
InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exp…
Update
|
CWE-787
Out-of-bounds Write
|
CVE-2024-49509
|
2024-11-16 09:35 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
80
|
5.5 |
MEDIUM
Local
|
adobe
|
indesign
|
InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerabi…
Update
|
CWE-125
Out-of-bounds Read
|
CVE-2024-49512
|
2024-11-16 09:34 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|