1071
|
- |
|
-
|
-
|
Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS allows Path Traversal.This issue affects WPLMS: from n/a before 1.9.9.5.2.
|
CWE-35
Path Traversal: '.../...//'
|
CVE-2024-56055
|
2024-12-19 04:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1072
|
- |
|
-
|
-
|
Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS allows Upload a Web Shell to a Web Server.This issue affects WPLMS: from n/a before 1.9.9.5.2.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-56054
|
2024-12-19 04:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1073
|
- |
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS allows SQL Injection.This issue affects WPLMS: from n/a before 1.9.9.5.3.
|
CWE-89
SQL Injection
|
CVE-2024-56053
|
2024-12-19 04:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1074
|
- |
|
-
|
-
|
Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS allows Upload a Web Shell to a Web Server.This issue affects WPLMS: from n/a before 1.9.9.5.2.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-56052
|
2024-12-19 04:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1075
|
- |
|
-
|
-
|
Improper Control of Generation of Code ('Code Injection') vulnerability in VibeThemes WPLMS allows Code Injection.This issue affects WPLMS: from n/a before 1.9.9.5.
|
CWE-94
Code Injection
|
CVE-2024-56051
|
2024-12-19 04:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1076
|
- |
|
-
|
-
|
Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS allows Upload a Web Shell to a Web Server.This issue affects WPLMS: from n/a before 1.9.9.5.3.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-56050
|
2024-12-19 04:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1077
|
- |
|
-
|
-
|
Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS allows Path Traversal.This issue affects WPLMS: from n/a before 1.9.9.5.2.
|
CWE-35
Path Traversal: '.../...//'
|
CVE-2024-56049
|
2024-12-19 04:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1078
|
- |
|
-
|
-
|
Missing Authorization vulnerability in VibeThemes WPLMS allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPLMS: from n/a through 1.9.9.
|
CWE-862
Missing Authorization
|
CVE-2024-56048
|
2024-12-19 04:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1079
|
- |
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS allows SQL Injection.This issue affects WPLMS: from n/a before 1.9.9.5.3.
|
CWE-89
SQL Injection
|
CVE-2024-56047
|
2024-12-19 04:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1080
|
- |
|
-
|
-
|
DataEase is an open source business analytics tool. Authenticated users can read and deserialize arbitrary files through the background JDBC connection. When constructing the jdbc connection string, …
|
CWE-89
SQL Injection
|
CVE-2024-55953
|
2024-12-19 04:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|