1451
|
7.7 |
HIGH
Network
|
hashicorp
|
terraform_enterprise
|
Terraform Enterprise since v202207-1 did not properly implement authorization rules for agent pools, allowing the workspace to be targeted by unauthorized agents. This authorization flaw could potent…
|
CWE-863
Incorrect Authorization
|
CVE-2023-3114
|
2024-09-27 05:15 |
2023-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1452
|
5.4 |
MEDIUM
Network
|
allprices
|
beauty
|
The Beauty theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tpl_featured_cat_id’ parameter in all versions up to, and including, 1.1.4 due to insufficient input sanitization …
|
CWE-79
Cross-site Scripting
|
CVE-2024-5884
|
2024-09-27 05:13 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1453
|
8.8 |
HIGH
Network
|
xwp
|
stream
|
The Stream plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.1. This is due to missing or incorrect nonce validation on the network_options_ac…
|
CWE-352
Origin Validation Error
|
CVE-2024-7423
|
2024-09-27 05:08 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1454
|
6.1 |
MEDIUM
Network
|
slicewp
|
affiliate_program_suite
|
The WordPress Affiliates Plugin — SliceWP Affiliates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8714
|
2024-09-27 05:06 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1455
|
6.1 |
MEDIUM
Network
|
leira
|
roles_\&_capabilities
|
The Roles & Capabilities plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and includ…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8732
|
2024-09-27 05:01 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1456
|
6.1 |
MEDIUM
Network
|
cvstech
|
exit_notifier
|
The Exit Notifier plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8730
|
2024-09-27 04:58 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1457
|
6.1 |
MEDIUM
Network
|
leira
|
cron_jobs
|
The Cron Jobs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.2.9.…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8731
|
2024-09-27 04:43 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1458
|
9.8 |
CRITICAL
Network
dedecms
|
dedecms
|
DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2023-40784
|
2024-09-27 04:35 |
2023-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1459
|
7.8 |
HIGH
Local
|
raidenftpd
|
raidenftpd
|
Buffer Overflow vulnerability in RaidenFTPD 2.4.4005 allows a local attacker to execute arbitrary code via the Server name field of the Step by step setup wizard.
|
CWE-120
Classic Buffer Overflow
|
CVE-2023-39063
|
2024-09-27 04:35 |
2023-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1460
|
8.0 |
HIGH
Adjacent
|
tp-link
|
archer_c3150_firmware
|
Archer C3150 firmware versions prior to 'Archer C3150(JP)_V2_230511' allows a network-adjacent authenticated attacker to execute arbitrary OS commands.
|
CWE-78
OS Command
|
CVE-2023-38588
|
2024-09-27 04:35 |
2023-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|