2551
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Affiliate Program Suite — SliceWP Affiliates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.23. This is due to missing or incorrect non…
|
CWE-352
Origin Validation Error
|
CVE-2024-12454
|
2024-12-18 19:15 |
2024-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2552
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Animation Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.6 via the 'render' function in widgets/content-slider…
|
CWE-200
Information Exposure
|
CVE-2024-12340
|
2024-12-18 19:15 |
2024-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2553
|
- |
|
-
|
-
|
An out-of-bounds read vulnerability was found in DPDK's Vhost library checksum offload feature. This issue enables an untrusted or compromised guest to crash the hypervisor's vSwitch by forging Virti…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-11614
|
2024-12-18 18:15 |
2024-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2554
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_event: Align BR/EDR JUST_WORKS paring with LE
This aligned BR/EDR JUST_WORKS method with LE which since 92516cd97f…
|
-
|
CVE-2024-53144
|
2024-12-18 17:15 |
2024-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2555
|
- |
|
-
|
-
|
Inclusion of undocumented features or chicken bits issue exists in AE1021 firmware versions 2.0.10 and earlier and AE1021PE firmware versions 2.0.10 and earlier, which may allow a logged-in user to e…
|
CWE-1242
Inclusion of Undocumented Features or Chicken Bits
|
CVE-2024-54457
|
2024-12-18 16:15 |
2024-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2556
|
- |
|
-
|
-
|
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in AE1021 firmware versions 2.0.10 and earlier and AE1021PE firmware versions 2.0.10 and earlie…
|
CWE-78
OS Command
|
CVE-2024-53688
|
2024-12-18 16:15 |
2024-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2557
|
- |
|
-
|
-
|
Weak authentication issue exists in AE1021 firmware versions 2.0.10 and earlier and AE1021PE firmware versions 2.0.10 and earlier. If this vulnerability is exploited, the authentication may be bypass…
|
CWE-1390
Weak Authentication
|
CVE-2024-47397
|
2024-12-18 16:15 |
2024-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2558
|
- |
|
-
|
-
|
In ThreatQuotient ThreatQ before 5.29.3, authenticated users are able to execute arbitrary commands by sending a crafted request to an API endpoint.
|
-
|
CVE-2024-39703
|
2024-12-18 16:15 |
2024-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2559
|
9.8 |
CRITICAL
Network
-
|
-
|
The Biagiotti Membership plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.0.2. This is due to the plugin not properly verifying a user's identity pr…
|
CWE-287
Improper Authentication
|
CVE-2024-12287
|
2024-12-18 16:15 |
2024-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2560
|
5.3 |
MEDIUM
Network
-
|
-
|
The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.29 via the WordPress core search feature. This makes …
|
CWE-200
Information Exposure
|
CVE-2024-11295
|
2024-12-18 16:15 |
2024-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|