1221
|
4.3 |
MEDIUM
Network
|
-
|
-
|
IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could allow an authenticated user to obtain sensitive informa…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2023-38271
|
2025-01-25 23:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1222
|
5.3 |
MEDIUM
Network
-
|
-
|
IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could disclose sensitive information in HTTP responses that c…
|
CWE-201
Insertion of Sensitive Information Into Sent Data
|
CVE-2023-38013
|
2025-01-25 23:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1223
|
5.3 |
MEDIUM
Network
-
|
-
|
IBM Cloud Pak System 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, and 2.3.4.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially…
|
CWE-22
Path Traversal
|
CVE-2023-38012
|
2025-01-25 23:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1224
|
7.5 |
HIGH
Network
-
|
-
|
The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.14.5 via the uploads dire…
|
CWE-200
Information Exposure
|
CVE-2024-13562
|
2025-01-25 21:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1225
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Divi Carousel Maker – Image, Logo, Testimonial, Post Carousel & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Carousel and Logo Carousel in all ver…
|
CWE-79
Cross-site Scripting
|
CVE-2025-0350
|
2025-01-25 19:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1226
|
3.8 |
LOW
Network
|
-
|
-
|
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all ve…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-13450
|
2025-01-25 18:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1227
|
5.3 |
MEDIUM
Network
-
|
-
|
The Boom Fest plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'bf_admin_action' function in all versions up to, and including, 2.2.1. …
|
CWE-862
Missing Authorization
|
CVE-2024-13449
|
2025-01-25 18:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1228
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.2.7.5 due to insufficient input sanitization and output…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13599
|
2025-01-25 17:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1229
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Masy Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'justified-gallery' shortcode in all versions up to, and including, 1.7 due to insufficient input s…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13586
|
2025-01-25 17:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1230
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The ABC Notation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'abcjs' shortcode in all versions up to, and including, 6.1.3 due to insufficient input sanitizatio…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13551
|
2025-01-25 17:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|