591
|
4.3 |
MEDIUM
Network
|
infiniteuploads
|
big_file_uploads
|
The Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.1.2. This is due the plugin not sanitizing …
|
CWE-22
Path Traversal
|
CVE-2024-8538
|
2024-09-27 01:28 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
592
|
9.8 |
CRITICAL
Network
wpcharitable
|
charitable
|
The Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.8.1.14. Thi…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-8791
|
2024-09-27 01:25 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
593
|
5.3 |
MEDIUM
Network
ba-booking
|
ba_book_everything
|
The BA Book Everything plugin for WordPress is vulnerable to arbitrary password reset in all versions up to, and including, 1.6.20. This is due to the reset_user_password() function not verifying a u…
|
NVD-CWE-Other
|
CVE-2024-8794
|
2024-09-27 01:23 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
594
|
6.1 |
MEDIUM
Network
|
ninjaforms
|
ninja_forms_file_uploads
|
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. RTX file) in all versions up to, and including, 3.3.16 due to insufficient …
|
CWE-79
Cross-site Scripting
|
CVE-2024-1596
|
2024-09-27 01:23 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
595
|
5.4 |
MEDIUM
Network
|
master-addons
|
master_addons
|
The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-jltma-wrapper-link element…
|
CWE-79
Cross-site Scripting
|
CVE-2024-6282
|
2024-09-27 01:19 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
596
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capa…
|
CWE-862
Missing Authorization
|
CVE-2024-8771
|
2024-09-27 01:15 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
597
|
4.4 |
MEDIUM
Network
|
-
|
-
|
A flaw was found in oVirt. A user with administrator privileges, including users with the ReadOnlyAdmin permission, may be able to use browser developer tools to view Provider passwords in cleartext.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2024-7259
|
2024-09-27 01:15 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
598
|
- |
|
-
|
-
|
Assimp v5.4.3 is vulnerable to Buffer Overflow via the MD5Importer::LoadMD5MeshFile function.
|
-
|
CVE-2024-46632
|
2024-09-27 01:15 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
599
|
- |
|
-
|
-
|
A Cross-Site Request Forgery (CSRF) vulnerability exists in kishan0725's Hospital Management System version 6.3.5. The vulnerability allows an attacker to craft a malicious HTML form that submits a r…
|
-
|
CVE-2024-45983
|
2024-09-27 01:15 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
600
|
7.2 |
HIGH
Network
|
-
|
-
|
IBM ManageIQ could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted yaml file request.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-43191
|
2024-09-27 01:15 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|