1111
|
2.7 |
LOW
Network
|
formtools
|
form_tools
|
A vulnerability, which was classified as problematic, was found in formtools.org Form Tools 3.1.1. Affected is the function curl_exec of the file /admin/forms/option_lists/edit.php of the component I…
|
NVD-CWE-Other
|
CVE-2024-6937
|
2024-10-2 01:51 |
2024-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1112
|
6.5 |
MEDIUM
Network
|
devolutions
|
devolutions_server
|
Authorization bypass in the PAM access request approval mechanism in Devolutions Server 2024.2.10 and earlier allows authenticated users with permissions to approve their own requests, bypassing inte…
|
CWE-863
Incorrect Authorization
|
CVE-2024-6512
|
2024-10-2 01:36 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1113
|
6.1 |
MEDIUM
Network
|
collne
|
welcart
|
The Welcart e-Commerce WordPress plugin before 2.9.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used ag…
|
CWE-79
Cross-site Scripting
|
CVE-2023-5951
|
2024-10-2 01:35 |
2023-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1114
|
5.4 |
MEDIUM
Network
|
uploading_svg\ _webp_and_ico_files_project
|
uploading_svg\ _webp_and_ico_files
|
The Uploading SVG, WEBP and ICO files WordPress plugin through 1.2.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XS…
|
CWE-79
Cross-site Scripting
|
CVE-2023-4460
|
2024-10-2 01:35 |
2023-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1115
|
5.3 |
MEDIUM
Network
microsoft
|
windows_server_2012 windows_server_2016 windows_server_2019 windows_server_2022
|
DHCP Server Service Information Disclosure Vulnerability
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2023-29355
|
2024-10-2 01:35 |
2023-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1116
|
5.3 |
MEDIUM
Network
atlassian
|
confluence_data_center confluence_server
|
Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a private Confluence space. This occurs via an Informa…
|
NVD-CWE-noinfo
|
CVE-2023-22503
|
2024-10-2 01:35 |
2023-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1117
|
5.4 |
MEDIUM
Network
|
strangerstudios
|
paid_memberships_pro
|
The Paid Memberships Pro WordPress plugin before 2.9.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as lo…
|
CWE-79
Cross-site Scripting
|
CVE-2022-4830
|
2024-10-2 01:35 |
2023-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1118
|
5.4 |
MEDIUM
Network
|
3dflipbook
|
3d_flipbook
|
The 3D FlipBook WordPress plugin through 1.13.2 does not validate or escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as Con…
|
CWE-79
Cross-site Scripting
|
CVE-2022-4453
|
2024-10-2 01:35 |
2023-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1119
|
9.8 |
CRITICAL
Network
doverfuelingsolutions
|
progauge_maglink_lx_console_firmware progauge_maglink_lx4_console_firmware
|
An attacker can directly request the ProGauge MAGLINK LX CONSOLE
resource sub page with full privileges by requesting the URL directly.
|
NVD-CWE-Other
|
CVE-2024-43692
|
2024-10-2 01:22 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1120
|
9.8 |
CRITICAL
Network
doverfuelingsolutions
|
progauge_maglink_lx_console_firmware progauge_maglink_lx4_console_firmware
|
A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE IP
sub-menu can allow a remote attacker to inject arbitrary commands.
|
CWE-77
Command Injection
|
CVE-2024-45066
|
2024-10-2 01:18 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|