401
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: added NULL check at start of dc_validate_stream
[Why]
prevent invalid memory access
[How]
check if dc and strea…
|
-
|
CVE-2024-46802
|
2024-09-27 22:15 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
402
|
- |
|
-
|
-
|
In Foxit PDF Reader before 2024.3, and PDF Editor before 2024.3 and 13.x before 13.1.4, an attacker can replace an update file with a Trojan horse via side loading, because the update service lacks i…
|
-
|
CVE-2024-41605
|
2024-09-27 22:15 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
403
|
8.8 |
HIGH
Network
|
acymailing
|
acymailing
|
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-7384
|
2024-09-27 22:15 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
404
|
6.6 |
MEDIUM
Local
|
linux fedoraproject redhat
|
linux_kernel fedora enterprise_linux
|
A flaw was found in the Netfilter subsystem in the Linux kernel. The issue is in the nft_byteorder_eval() function, where the code iterates through a loop and writes to the `dst` array. On each itera…
|
NVD-CWE-Other
|
CVE-2024-0607
|
2024-09-27 22:15 |
2024-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
405
|
8.8 |
HIGH
Network
|
wpmarketingrobot
|
woocommerce_google_feed_manager
|
The WooCommerce Google Feed Manager plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'wppfm_removeFeedFile' function in all versions up to, and…
|
CWE-862
Missing Authorization
|
CVE-2024-7258
|
2024-09-27 22:05 |
2024-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
406
|
4.3 |
MEDIUM
Network
|
webba-booking
|
webba_booking
|
The Appointment & Event Booking Calendar Plugin – Webba Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_appearance() func…
|
CWE-862
Missing Authorization
|
CVE-2024-8432
|
2024-09-27 21:58 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
407
|
6.1 |
MEDIUM
Network
|
fatcatapps
|
pixel_cat
|
The Pixel Cat – Conversion Pixel Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions u…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8544
|
2024-09-27 21:57 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
408
|
5.4 |
MEDIUM
Network
|
ggnome
|
garden_gnome_package
|
The Garden Gnome Package plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ggpkg shortcode in all versions up to, and including, 2.2.9 due to insufficient input sanit…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8657
|
2024-09-27 21:56 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
409
|
6.1 |
MEDIUM
Network
|
ibericode
|
koko_analytics
|
The Koko Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8662
|
2024-09-27 21:54 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
410
|
4.3 |
MEDIUM
Network
|
themify
|
themify_builder
|
The Themify Builder plugin for WordPress is vulnerable to unauthorized post duplication due to missing checks on the duplicate_page_ajaxify function in all versions up to, and including, 7.6.1. This …
|
CWE-863
Incorrect Authorization
|
CVE-2024-7836
|
2024-09-27 21:53 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|