521
|
- |
|
-
|
-
|
A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been declared as critical. Affected by this vulnerability is the function cgi_user_add of the file …
New
|
CWE-78 CWE-74 CWE-707
OS Command Injection Improper Enforcement of Message or Data Structure
|
CVE-2024-10914
|
2024-11-7 03:17 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
522
|
- |
|
-
|
-
|
Improper Input Validation vulnerability in OpenText iManager allows Cross-Site Scripting (XSS). This issue affects iManager before 3.2.3
New
|
-
|
CVE-2020-11859
|
2024-11-7 03:17 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
523
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's events_cal shortcode in all versions up to, and including, 5.9.6 due to insufficient input sanitizati…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-10186
|
2024-11-7 03:17 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
524
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Pricing Tables WordPress Plugin – Easy Pricing Tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘fontFamily’ attribute in all versions up to, and including, 3.2.6 …
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-8323
|
2024-11-7 03:17 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
525
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woot_button shortcode in all versions u…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-10168
|
2024-11-7 03:17 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
526
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Map block in all versions up to, and including, 2.94.1 due to insufficient input san…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-10715
|
2024-11-7 03:17 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
527
|
6.3 |
MEDIUM
Local
|
-
|
-
|
A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace the contents of any file on any system path and take ownership of it when a pr…
New
|
CWE-863
Incorrect Authorization
|
CVE-2024-9902
|
2024-11-7 03:17 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
528
|
10.0 |
CRITICAL
Network
-
|
-
|
The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_location_load_excel_file_callback() function in all versio…
New
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-8615
|
2024-11-7 03:17 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
529
|
9.9 |
CRITICAL
Network
|
-
|
-
|
The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_wp_handle_upload() function in all versions up to, and inc…
New
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-8614
|
2024-11-7 03:17 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
530
|
- |
|
-
|
-
|
When curl is asked to use HSTS, the expiry time for a subdomain might
overwrite a parent domain's cache entry, making it end sooner or later than
otherwise intended.
This affects curl using applicat…
New
|
-
|
CVE-2024-9681
|
2024-11-7 03:17 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|