61
|
- |
|
-
|
-
|
Missing Authorization vulnerability in W3 Eden, Inc. Download Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Manager: from n/a through 3.3…
New
|
CWE-862
Missing Authorization
|
CVE-2024-56217
|
2024-12-31 20:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
62
|
- |
|
-
|
-
|
Missing Authorization vulnerability in Stephen Sherrard Member Directory and Contact Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Member Directory a…
New
|
CWE-862
Missing Authorization
|
CVE-2024-56215
|
2024-12-31 20:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
63
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DeluxeThemes Userpro allows Reflected XSS.This issue affects Userpro: from n/a through 5.1.9.
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-56210
|
2024-12-31 20:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
64
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SeventhQueen Kleo allows Reflected XSS.This issue affects Kleo: from n/a before 5.4.4.
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-56209
|
2024-12-31 20:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
65
|
- |
|
-
|
-
|
In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public API.
New
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2024-12108
|
2024-12-31 20:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
66
|
- |
|
-
|
-
|
In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings.
New
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2024-12106
|
2024-12-31 20:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
67
|
- |
|
-
|
-
|
In WhatsUp Gold versions released before 2024.0.2, an authenticated user can use a specially crafted HTTP request that can lead to information disclosure.
New
|
CWE-22
Path Traversal
|
CVE-2024-12105
|
2024-12-31 20:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
68
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in Alexander Volkov WP Nice Loader allows Stored XSS.This issue affects WP Nice Loader: from n/a through 0.1.0.4.
New
|
CWE-352
Origin Validation Error
|
CVE-2024-56232
|
2024-12-31 19:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
69
|
- |
|
-
|
-
|
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Dynamic Web Lab Dynamic Product Category Grid, Slider for WooCommerce allows P…
New
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2024-56230
|
2024-12-31 19:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
70
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in Searchiq SearchIQ.This issue affects SearchIQ: from n/a through 4.6.
New
|
CWE-352
Origin Validation Error
|
CVE-2024-56229
|
2024-12-31 19:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|