931
|
- |
|
-
|
-
|
Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for an authenticated malicious client to tamper with audit log creation in AXIS Camera Station, or perf…
|
-
|
CVE-2024-7696
|
2025-01-7 15:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
932
|
7.5 |
HIGH
Network
-
|
-
|
The Error Log Viewer By WP Guru plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.0.1.3 via the wp_ajax_nopriv_elvwp_log_download AJAX action. This mak…
|
CWE-22
Path Traversal
|
CVE-2024-12849
|
2025-01-7 15:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
933
|
7.1 |
HIGH
Network
|
-
|
-
|
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page parameter in all versions up to, and including, 5…
|
CWE-79
Cross-site Scripting
|
CVE-2024-12633
|
2025-01-7 15:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
934
|
8.6 |
HIGH
Network
-
|
-
|
The Host PHP Info plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when including the 'phpinfo' function in all versions up to, and including, 1.0.4…
|
CWE-862
Missing Authorization
|
CVE-2024-12535
|
2025-01-7 15:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
935
|
8.8 |
HIGH
Network
|
-
|
-
|
The Post Saint: ChatGPT, GPT4, DALL-E, Stable Diffusion, Pexels, Dezgo AI Text & Image Generator plugin for WordPress is vulnerable to arbitrary files uploads due to a missing capability check and fi…
|
CWE-94
Code Injection
|
CVE-2024-12471
|
2025-01-7 15:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
936
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Chatroll Live Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'chatroll' shortcode in all versions up to, and including, 2.5.0 due to insufficient input sa…
|
CWE-79
Cross-site Scripting
|
CVE-2024-12464
|
2025-01-7 15:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
937
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Candifly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'candifly' shortcode in all versions up to, and including, 1.0.6 due to insufficient input sanitization…
|
CWE-79
Cross-site Scripting
|
CVE-2024-12440
|
2025-01-7 15:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
938
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Marketplace Items plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'marketplace' shortcode in all versions up to, and including, 1.5.5 due to insufficient input …
|
CWE-79
Cross-site Scripting
|
CVE-2024-12439
|
2025-01-7 15:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
939
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The WooCommerce Digital Content Delivery (incl. DRM) – FlickRocket plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'start_date’ and 'end_date' parameters in all versions …
|
CWE-79
Cross-site Scripting
|
CVE-2024-12438
|
2025-01-7 15:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
940
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Binary MLM Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page’ parameter in all versions up to, and including, 2.0 due to insufficient input sanitizati…
|
CWE-79
Cross-site Scripting
|
CVE-2024-12384
|
2025-01-7 15:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|