751
|
- |
|
-
|
-
|
The Dyn Business Panel WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used a…
|
-
|
CVE-2024-13055
|
2025-01-27 15:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
752
|
- |
|
-
|
-
|
The Dental Optimizer Patient Generator App WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting whi…
|
-
|
CVE-2024-13052
|
2025-01-27 15:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
753
|
- |
|
-
|
-
|
The Altra Side Menu WordPress plugin through 2.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
|
-
|
CVE-2024-12773
|
2025-01-27 15:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
754
|
- |
|
-
|
-
|
The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
|
-
|
CVE-2024-12436
|
2025-01-27 15:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
755
|
- |
|
-
|
-
|
The WC Affiliate WordPress plugin through 2.3.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used agains…
|
-
|
CVE-2024-12321
|
2025-01-27 15:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
756
|
4.8 |
MEDIUM
Network
|
-
|
-
|
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get …
|
CWE-614
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
|
CVE-2024-28771
|
2025-01-27 11:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
757
|
4.8 |
MEDIUM
Network
|
-
|
-
|
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get …
|
CWE-614
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
|
CVE-2024-28770
|
2025-01-27 11:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
758
|
2.4 |
LOW
Adjacent
|
-
|
-
|
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could disclose sensitive information about directory contents that could aid in further attacks against the…
|
CWE-548
Exposure of Information Through Directory Listing
|
CVE-2024-28766
|
2025-01-27 11:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
759
|
5.4 |
MEDIUM
Network
|
-
|
-
|
IBM InfoSphere Master Data Management 11.6, 12.0, and 14.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering…
|
CWE-79
Cross-site Scripting
|
CVE-2023-46187
|
2025-01-27 11:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
760
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability classified as critical was found in needyamin image_gallery 1.0. This vulnerability affects unknown code of the file /admin/gallery.php of the component Cover Image Handler. The manip…
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2025-0722
|
2025-01-27 09:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|