981
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Eventer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.9.7 via the eventer_woo_download_tickets() function. This makes it possible for authentic…
|
CWE-22
Path Traversal
|
CVE-2024-10799
|
2025-01-17 15:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
982
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The WP Inventory Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' parameter in all versions up to, and including, 2.3.2 due to insufficient input sanitiz…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13434
|
2025-01-17 14:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
983
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Payment Button for PayPal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_paypal_checkout' shortcode in all versions up to, and including, 1.2.3.35 due to i…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13401
|
2025-01-17 14:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
984
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Checkout for PayPal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'checkout_for_paypal' shortcode in all versions up to, and including, 1.0.32 due to insuffic…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13398
|
2025-01-17 14:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
985
|
4.0 |
MEDIUM
Local
|
-
|
-
|
IBM QRadar WinCollect Agent 10.0.0 through 10.1.12 could allow a remote attacker to inject XML data into parameter values due to improper input validation of assumed immutable data.
|
CWE-471
Modification of Assumed-Immutable Data (MAID)
|
CVE-2024-51462
|
2025-01-17 12:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
986
|
- |
|
-
|
-
|
A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an arbitrary file.
|
-
|
CVE-2024-12806
|
2025-01-17 12:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
987
|
- |
|
-
|
-
|
A post-authentication format string vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution.
|
-
|
CVE-2024-12805
|
2025-01-17 12:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
988
|
- |
|
-
|
-
|
A post-authentication stack-based buffer overflow vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution.
|
-
|
CVE-2024-12803
|
2025-01-17 12:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
989
|
6.5 |
MEDIUM
Network
|
-
|
-
|
IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../…
|
CWE-22
Path Traversal
|
CVE-2024-52363
|
2025-01-17 11:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
990
|
7.8 |
HIGH
Local
|
-
|
-
|
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2025-21325
|
2025-01-17 10:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|