2091
|
8.8 |
HIGH
Network
|
-
|
-
|
The Stream plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.1. This is due to missing or incorrect nonce validation on the network_options_ac…
|
CWE-352
Origin Validation Error
|
CVE-2024-7423
|
2024-09-14 01:37 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2092
|
5.3 |
MEDIUM
Network
-
|
-
|
The Custom Post Limits plugin for WordPress is vulnerable to full path disclosure in all versions up to, and including, 4.4.1. This is due to the plugin utilizing bootstrap and leaving test files wit…
|
CWE-200
Information Exposure
|
CVE-2024-6544
|
2024-09-14 01:37 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2093
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Beauty theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tpl_featured_cat_id’ parameter in all versions up to, and including, 1.1.4 due to insufficient input sanitization …
|
CWE-79
Cross-site Scripting
|
CVE-2024-5884
|
2024-09-14 01:37 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2094
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Tweaker5 theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's Button shortcode in all versions up to, and including, 1.2 due to insufficient…
|
CWE-79
Cross-site Scripting
|
CVE-2024-5870
|
2024-09-14 01:37 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2095
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Neighborly theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's Button shortcode in all versions up to, and including, 1.4 due to insufficie…
|
CWE-79
Cross-site Scripting
|
CVE-2024-5869
|
2024-09-14 01:37 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2096
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Delicate theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' parameter within the theme's Button shortcode in all versions up to, and including, 3.5.5 due to insuffici…
|
-
|
CVE-2024-5867
|
2024-09-14 01:37 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2097
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Triton Lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute within the theme's Button shortcode in all versions up to, and including, 1.3 due to insuffici…
|
CWE-79
Cross-site Scripting
|
CVE-2024-5789
|
2024-09-14 01:37 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2098
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
perf/aux: Fix AUX buffer serialization
Ole reported that event->mmap_mutex is strictly insufficient to
serialize the AUX buffer, …
|
-
|
CVE-2024-46713
|
2024-09-14 01:37 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2099
|
7.2 |
HIGH
Network
|
-
|
-
|
The WP Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'current_theme_root' parameter in versions up to, and including 1.2.9. This makes it possible for authen…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2022-2446
|
2024-09-14 01:37 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2100
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
memcg_write_event_control(): fix a user-triggerable oops
we are *not* guaranteed that anything past the terminating NUL
is mapped…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-45021
|
2024-09-14 01:36 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|