1141
|
5.4 |
MEDIUM
Network
|
mappresspro
|
mappress
|
The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the width and height parameters in all versions up to, and including, 2.88.16 due to insufficient…
|
CWE-79
Cross-site Scripting
|
CVE-2023-7225
|
2024-11-14 02:43 |
2024-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1142
|
9.8 |
CRITICAL
Network
mappresspro
|
mappress
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Chris Richardson MapPress Maps for WordPress mappress-google-maps-for-wordpress allows SQL Inject…
|
CWE-89
SQL Injection
|
CVE-2023-26015
|
2024-11-14 02:43 |
2023-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1143
|
5.4 |
MEDIUM
Network
|
mappresspro
|
mappress
|
The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'mappress' shortcode in versions up to, and including, 2.88.4 due to insufficient input sanitizat…
|
-
|
CVE-2023-4840
|
2024-11-14 02:43 |
2023-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1144
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: Add rough attr alloc_size check
|
NVD-CWE-noinfo
|
CVE-2024-50246
|
2024-11-14 02:38 |
2024-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1145
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
nvmet-auth: assign dh_key to NULL after kfree_sensitive
ctrl->dh_key might be used across multiple calls to nvmet_setup_dhgroup()…
|
CWE-415
Double Free
|
CVE-2024-50215
|
2024-11-14 02:35 |
2024-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1146
|
- |
|
-
|
-
|
MENDELSON AS4 before 2024 B376 has a client-side vulnerability when a trading partner provides prepared XML data. When a victim opens the details of this transaction in the client, files can be writt…
|
-
|
CVE-2024-39334
|
2024-11-14 02:35 |
2024-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1147
|
7.5 |
HIGH
Network
jenkins
|
credentials
|
Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the `SecretBytes` type when accessing item `confi…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2024-47805
|
2024-11-14 02:32 |
2024-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1148
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: Fix possible deadlock in mi_read
Mutex lock with another subclass used in ni_lock_dir().
|
NVD-CWE-noinfo
|
CVE-2024-50245
|
2024-11-14 02:29 |
2024-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1149
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: Additional check in ni_clear()
Checking of NTFS_FLAGS_LOG_REPLAYING added to prevent access to
uninitialized bitmap dur…
|
NVD-CWE-noinfo
|
CVE-2024-50244
|
2024-11-14 02:28 |
2024-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1150
|
4.3 |
MEDIUM
Network
|
jenkins
|
jenkins
|
If an attempt is made to create an item of a type prohibited by `ACL#hasCreatePermission2` or `TopLevelItemDescriptor#isApplicableIn(ItemGroup)` through the Jenkins CLI or the REST API and either of …
|
NVD-CWE-noinfo
|
CVE-2024-47804
|
2024-11-14 02:28 |
2024-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|