811
|
- |
|
-
|
-
|
Incorrect access control in Tenda AC1200 Smart Dual-Band WiFi Router Model AC6 v2.0 Firmware v15.03.06.50 allows attackers to bypass authentication via a crafted web request.
|
-
|
CVE-2024-46450
|
2025-01-17 07:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
812
|
8.5 |
HIGH
Network
|
boldgrid
|
w3_total_cache
|
The W3 Total Cache plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is_w3tc_admin_page function in all versions up to, and including, 2.8.1. …
|
CWE-862
Missing Authorization
|
CVE-2024-12365
|
2025-01-17 06:31 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
813
|
7.5 |
HIGH
Network
boldgrid
|
w3_total_cache
|
The W3 Total Cache plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.8.1 through the publicly exposed debug log file. This makes it possible for unaut…
|
NVD-CWE-noinfo
|
CVE-2024-12008
|
2025-01-17 06:30 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
814
|
5.3 |
MEDIUM
Network
boldgrid
|
w3_total_cache
|
The W3 Total Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 2.8.1. This mak…
|
CWE-862
Missing Authorization
|
CVE-2024-12006
|
2025-01-17 06:30 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
815
|
5.4 |
MEDIUM
Network
|
themeisle
|
orbit_fox
|
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Table widget in all versions up to, and including, 2.10.43 due to insufficient in…
|
CWE-79
Cross-site Scripting
|
CVE-2025-0311
|
2025-01-17 06:29 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
816
|
5.4 |
MEDIUM
Network
|
themeisle
|
orbit_fox
|
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_tag’ parameter in all versions up to, and including, 2.10.43 due to insufficient input sani…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13183
|
2025-01-17 06:28 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
817
|
7.2 |
HIGH
Network
|
simple-help
|
simplehelp
|
SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to…
|
CWE-59
Link Following
|
CVE-2024-57728
|
2025-01-17 06:24 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
818
|
7.5 |
HIGH
Network
simple-help
|
simplehelp
|
SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleH…
|
CWE-22
Path Traversal
|
CVE-2024-57727
|
2025-01-17 06:22 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
819
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kopatheme Kopa Nictitate Toolkit allows Stored XSS.This issue affects Kopa Nictitate Toolkit: fro…
|
CWE-79
Cross-site Scripting
|
CVE-2025-23965
|
2025-01-17 06:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
820
|
- |
|
-
|
-
|
Missing Authorization vulnerability in Sven Hofmann & Michael Schoenrock Mark Posts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mark Posts: from n/a thr…
|
CWE-862
Missing Authorization
|
CVE-2025-23963
|
2025-01-17 06:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|