1971
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Property Hive Mortgage Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘price’ parameter in all versions up to, and including, 1.0.6 due to insufficient input…
|
CWE-79
Cross-site Scripting
|
CVE-2024-11940
|
2024-12-10 18:15 |
2024-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1972
|
- |
|
-
|
-
|
If the attacker has access to a valid Poweruser session, remote code execution is possible because specially crafted valid PNG files with injected PHP content can be uploaded as desktop backgrounds o…
|
-
|
CVE-2024-47946
|
2024-12-10 17:15 |
2024-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1973
|
7.7 |
HIGH
Network
|
-
|
-
|
The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.26. This makes it possible for authenticated attacke…
|
CWE-25
|
CVE-2023-6947
|
2024-12-10 15:15 |
2024-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1974
|
- |
|
-
|
-
|
Versions of the package luigi before 3.6.0 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) due to improper destination file path validation in the _extract_packages_archive f…
|
-
|
CVE-2024-21542
|
2024-12-10 14:15 |
2024-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1975
|
8.5 |
HIGH
Network
|
-
|
-
|
The WPForms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpforms_is_admin_page' function in versions starting from 1.8.4 up to, an…
|
CWE-862
Missing Authorization
|
CVE-2024-11205
|
2024-12-10 14:15 |
2024-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1976
|
- |
|
-
|
-
|
Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train) and prior to RCM 3.7.6.0 (for RCM 3.7.x train), Dell …
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2024-37144
|
2024-12-10 12:15 |
2024-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1977
|
- |
|
-
|
-
|
Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train) and prior to RCM 3.7.6.0 (for RCM 3.7.x train), Dell …
|
CWE-59
Link Following
|
CVE-2024-37143
|
2024-12-10 12:15 |
2024-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1978
|
- |
|
-
|
-
|
In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function Call (RFC) request to restricted destinations, which can be used to expose cre…
|
CWE-914
|
CVE-2024-54198
|
2024-12-10 10:15 |
2024-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1979
|
- |
|
-
|
-
|
SAP NetWeaver Administrator(System Overview) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploit…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-54197
|
2024-12-10 10:15 |
2024-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1980
|
- |
|
-
|
-
|
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to gain higher access levels than they should have by exploiting improper authorization checks, resulting …
|
CWE-862
Missing Authorization
|
CVE-2024-47585
|
2024-12-10 10:15 |
2024-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|