2201
|
7.3 |
HIGH
Network
-
|
-
|
The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.03. This is due to the software allowing users to execute an act…
|
CWE-94
Code Injection
|
CVE-2024-11740
|
2024-12-19 15:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2202
|
- |
|
-
|
-
|
CA Client Automation (ITCM) allows non-admin/non-root users to encrypt a string using CAF CLI and SD_ACMD CLI. This would allow the non admin user to access the critical encryption keys which further…
|
-
|
CVE-2024-38499
|
2024-12-19 15:15 |
2024-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2203
|
- |
|
-
|
-
|
Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability. A low privileged attacker with local access could potentially exploit thi…
|
CWE-88
Argument Injection
|
CVE-2024-51532
|
2024-12-19 11:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2204
|
7.8 |
HIGH
Local
|
-
|
-
|
IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to execution of unnecessary privileges.
|
CWE-250
Execution with Unnecessary Privileges
|
CVE-2024-35141
|
2024-12-19 11:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2205
|
5.4 |
MEDIUM
Network
|
-
|
-
|
The Broken Link Checker | Finder plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.5.0 via the 'moblc_check_link' function. This makes it…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-12121
|
2024-12-19 11:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2206
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The WP Project Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.15 via the Project Task List ('/wp-json/pm/v2/projects/1/task-lis…
|
CWE-200
Information Exposure
|
CVE-2024-10548
|
2024-12-19 11:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2207
|
5.3 |
MEDIUM
Network
|
-
|
-
|
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2023-30443
|
2024-12-19 11:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2208
|
- |
|
-
|
-
|
A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrat…
|
CWE-79
Cross-site Scripting
|
CVE-2023-23357
|
2024-12-19 11:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2209
|
- |
|
-
|
-
|
A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access…
|
CWE-78 CWE-77
OS Command Command Injection
|
CVE-2023-23356
|
2024-12-19 11:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2210
|
- |
|
-
|
-
|
A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access…
|
CWE-79
Cross-site Scripting
|
CVE-2023-23354
|
2024-12-19 11:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|