1901
|
8.8 |
HIGH
Network
|
hfo4
|
shudong-share
|
A vulnerability was found in HFO4 shudong-share 2.4.7. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /includes/fileReceive.php of the compon…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-8338
|
2024-09-26 04:12 |
2024-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1902
|
5.3 |
MEDIUM
Network
getastra
|
wp_hardening
|
The WP Hardening – Fix Your WordPress Security plugin for WordPress is vulnerable to Security Feature Bypass in all versions up to, and including, 1.2.6. This is due to use of an incorrect regular ex…
|
CWE-697
Incorrect Comparison
|
CVE-2024-6641
|
2024-09-26 04:07 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1903
|
6.1 |
MEDIUM
Network
|
svelte
|
svelte
|
svelte performance oriented web framework. A potential mXSS vulnerability exists in Svelte for versions up to but not including 4.2.19. Svelte improperly escapes HTML on server-side rendering. The as…
|
CWE-79
Cross-site Scripting
|
CVE-2024-45047
|
2024-09-26 04:06 |
2024-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1904
|
6.1 |
MEDIUM
Network
|
elizsoftware
|
panel
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Eliz Software Panel allows Reflected XSS.This issue affects Panel: before v2.3.24.
|
CWE-79
Cross-site Scripting
|
CVE-2024-6877
|
2024-09-26 03:57 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1905
|
6.2 |
MEDIUM
Local
|
redhat
|
libvirt
|
A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corner case on platforms where allocating 0 bytes of memory results in a NULL pointe…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-8235
|
2024-09-26 03:56 |
2024-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1906
|
9.8 |
CRITICAL
Network
elizsoftware
|
panel
|
Plaintext Storage of a Password vulnerability in Eliz Software Panel allows : Use of Known Domain Credentials.This issue affects Panel: before v2.3.24.
|
CWE-256
Plaintext Storage of a Password
|
CVE-2024-5960
|
2024-09-26 03:55 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1907
|
5.3 |
MEDIUM
Network
felixmoira
|
limit_login_attempts_plus
|
The Limit Login Attempts Plus plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.1.0. This is due to insufficient restrictions on where the IP Address infor…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2022-4533
|
2024-09-26 03:53 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1908
|
6.1 |
MEDIUM
Network
|
ibericode
|
mailchimp
|
The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email' parameter when a placeholder such as {email} is used for the field in versions …
|
CWE-79
Cross-site Scripting
|
CVE-2024-8850
|
2024-09-26 03:49 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1909
|
8.8 |
HIGH
Network
|
jeanmarc77
|
123solar
|
A vulnerability was found in jeanmarc77 123solar 1.8.4.5. It has been rated as critical. Affected by this issue is some unknown functionality of the file config/config_invt1.php. The manipulation of …
|
CWE-94
Code Injection
|
CVE-2024-9006
|
2024-09-26 03:44 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1910
|
5.4 |
MEDIUM
Network
|
jeanmarc77
|
123solar
|
A vulnerability classified as problematic has been found in jeanmarc77 123solar 1.8.4.5. This affects an unknown part of the file /detailed.php. The manipulation of the argument date1 leads to cross …
|
CWE-79
Cross-site Scripting
|
CVE-2024-9007
|
2024-09-26 03:40 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|