611
|
7.5 |
HIGH
Network
-
|
-
|
An unauthenticated remote attacker can cause a DoS in the controller due to uncontrolled resource consumption.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2018-25108
|
2025-01-16 20:15 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
612
|
- |
|
-
|
-
|
A weak authentication in Fortinet FortiManager Cloud, FortiAnalyzer versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiAnalyzer Cloud versions 7.4.1 through 7.4.3, FortiManager versions 7.6.0 th…
|
CWE-1390
Weak Authentication
|
CVE-2024-50563
|
2025-01-16 19:15 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
613
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The WP Responsive Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprtabs' shortcode in all versions up to, and including, 1.2.9 due to insufficient input san…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13387
|
2025-01-16 19:15 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
614
|
5.4 |
MEDIUM
Network
|
-
|
-
|
The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to limited file uploads due to insufficient file type validation in the upload_file() functi…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-13355
|
2025-01-16 19:15 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
615
|
5.3 |
MEDIUM
Network
-
|
-
|
The Multi Step Form plugin for WordPress is vulnerable to unauthorized limited file upload due to a missing capability check on the fw_upload_file AJAX action in all versions up to, and including, 1.…
|
CWE-862
Missing Authorization
|
CVE-2024-12427
|
2025-01-16 19:15 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
616
|
- |
|
-
|
-
|
A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiRecorder versions 7.2.0 through 7.2.1, 7.0.0 through 7.0.4, FortiWeb versions 7.6.0, 7.4.0 through 7.…
|
CWE-22
Path Traversal
|
CVE-2024-48885
|
2025-01-16 18:15 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
617
|
- |
|
-
|
-
|
A incorrect privilege assignment in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15, FortiManager versions 7.4.0 through 7.4.2, 7.…
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2024-45331
|
2025-01-16 18:15 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
618
|
- |
|
-
|
-
|
In affected versions of the Octopus Kubernetes worker or agent, sensitive variables could be written to the Kubernetes script pod log in clear-text. This was identified in Version 2 however it was de…
|
-
|
CVE-2024-12226
|
2025-01-16 16:15 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
619
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Chamber Dashboard Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'business_categories' shortcode in all versions up to, and including, 3.3.8…
|
CWE-79
Cross-site Scripting
|
CVE-2024-11452
|
2025-01-16 13:15 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
620
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The WP User Profile Avatar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.5. This is due to missing or incorrect nonce validation on the wp…
|
CWE-352
Origin Validation Error
|
CVE-2024-10789
|
2025-01-16 13:15 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|