1421
|
6.5 |
MEDIUM
Network
|
mediajedi
|
user_private_files
|
The User Private Files – WordPress File Sharing Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.0 via the 'dpk_upvf_update_doc'…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-7848
|
2024-09-27 07:12 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1422
|
5.3 |
MEDIUM
Network
maxfoundry
|
maxbuttons
|
The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 9.7.8. This makes it possible for unauthenticated attackers to …
|
NVD-CWE-noinfo
|
CVE-2024-6499
|
2024-09-27 07:07 |
2024-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1423
|
5.4 |
MEDIUM
Network
|
pixelgrade
|
nova_blocks
|
The Nova Blocks by Pixelgrade plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' attribute of the 'wp:separator' Gutenberg block in all versions up to, and including, 2…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8241
|
2024-09-27 07:03 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1424
|
4.3 |
MEDIUM
Network
|
themeum
|
tutor_lms
|
The Tutor LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.4. This is due to missing or incorrect nonce validation on the 'addon_enable_disab…
|
CWE-352
Origin Validation Error
|
CVE-2023-2919
|
2024-09-27 06:59 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1425
|
8.8 |
HIGH
Network
|
ultimatemember
|
forumwp
|
The ForumWP – Forum & Discussion Board Plugin plugin for WordPress is vulnerable to Privilege Escalation via Insecure Direct Object Reference in all versions up to, and including, 2.0.2 via the submi…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-8428
|
2024-09-27 06:58 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1426
|
8.8 |
HIGH
Network
|
tribulant
|
newsletters
|
The Newsletters plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.9.9.2. This is due to the plugin not restricting what user meta can be updated as sc…
|
NVD-CWE-noinfo
|
CVE-2024-8247
|
2024-09-27 06:49 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1427
|
4.3 |
MEDIUM
Network
|
jetplugs
|
revision_manager_tmc
|
The Revision Manager TMC plugin for WordPress is vulnerable to unauthorized arbitrary email sending due to a missing capability check on the _a_ajaxQuickEmailTestCallback() function in all versions u…
|
CWE-862
Missing Authorization
|
CVE-2024-7622
|
2024-09-27 06:42 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1428
|
7.5 |
HIGH
Network
openplcproject
|
openplc_v3_firmware
|
Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a36d95b73e7b8722d0edb8b9c5bb56a. A specially crafted EtherNet…
|
CWE-704
Incorrect Type Conversion or Cast
|
CVE-2024-39589
|
2024-09-27 06:36 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1429
|
8.8 |
HIGH
Network
|
jenkins
|
ssh2_easy
|
Jenkins SSH2 Easy Plugin 1.4 and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional permissions, like Overa…
|
CWE-281
Improper Preservation of Permissions
|
CVE-2023-41939
|
2024-09-27 06:35 |
2023-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1430
|
8.8 |
HIGH
Adjacent
|
tp-link
|
archer_c55_firmware archer_c50_v3_firmware
|
Archer C50 firmware versions prior to 'Archer C50(JP)_V3_230505' and Archer C55 firmware versions prior to 'Archer C55(JP)_V1_230506' use hard-coded credentials to login to the affected device, which…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2023-32619
|
2024-09-27 06:35 |
2023-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|