1051
|
- |
|
-
|
-
|
Unrestricted Upload of File with Dangerous Type vulnerability in David DONISA WP donimedia carousel allows Upload a Web Shell to a Web Server.This issue affects WP donimedia carousel: from n/a throug…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-50511
|
2024-11-1 21:57 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1052
|
- |
|
-
|
-
|
Unrestricted Upload of File with Dangerous Type vulnerability in Web and Print Design AR For Woocommerce allows Upload a Web Shell to a Web Server.This issue affects AR For Woocommerce: from n/a thro…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-50510
|
2024-11-1 21:57 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1053
|
- |
|
-
|
-
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Chetan Khandla Woocommerce Product Design allows Path Traversal.This issue affects Woocommerce Product …
|
CWE-22
Path Traversal
|
CVE-2024-50509
|
2024-11-1 21:57 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1054
|
- |
|
-
|
-
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Chetan Khandla Woocommerce Product Design allows Path Traversal.This issue affects Woocommerce Product …
|
CWE-22
Path Traversal
|
CVE-2024-50508
|
2024-11-1 21:57 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1055
|
- |
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in Daniel Schmitzer DS.DownloadList allows Object Injection.This issue affects DS.DownloadList: from n/a through 1.3.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-50507
|
2024-11-1 21:57 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1056
|
- |
|
-
|
-
|
Incorrect Privilege Assignment vulnerability in Azexo Marketing Automation by AZEXO allows Privilege Escalation.This issue affects Marketing Automation by AZEXO: from n/a through 1.27.80.
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2024-50506
|
2024-11-1 21:57 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1057
|
- |
|
-
|
-
|
Incorrect Privilege Assignment vulnerability in Matt Whiteman Bulk Change Role allows Privilege Escalation.This issue affects Bulk Change Role: from n/a through 1.1.
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2024-50504
|
2024-11-1 21:57 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1058
|
- |
|
-
|
-
|
Authentication Bypass Using an Alternate Path or Channel vulnerability in Deryck Oñate User Toolkit allows Authentication Bypass.This issue affects User Toolkit: from n/a through 1.2.3.
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2024-50503
|
2024-11-1 21:57 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1059
|
- |
|
-
|
-
|
The Download Manager WordPress plugin before 3.3.00 doesn't sanitize some of it's shortcode parameters, leading to cross site scripting.
|
-
|
CVE-2024-8444
|
2024-11-1 21:57 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1060
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The WP Team – WordPress Team Member Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's htteamember shortcode in all versions up to, and including, 1.1.4 due to …
|
CWE-79
Cross-site Scripting
|
CVE-2024-10223
|
2024-11-1 21:57 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|