1871
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2…
|
CWE-352
Origin Validation Error
|
CVE-2024-12636
|
2024-12-25 14:15 |
2024-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1872
|
7.5 |
HIGH
Network
-
|
-
|
The WP Data Access – App, Table, Form and Chart Builder plugin plugin for WordPress is vulnerable to SQL Injection via the 'order[user_login][dir]' parameter in all versions up to, and including, 5.5…
|
CWE-89
SQL Injection
|
CVE-2024-12428
|
2024-12-25 14:15 |
2024-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1873
|
- |
|
-
|
-
|
In OPPOStore iOS App, there's a possible escalation of privilege due to improper input validation.
|
-
|
CVE-2024-1609
|
2024-12-25 13:15 |
2024-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1874
|
5.3 |
MEDIUM
Network
-
|
-
|
The MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several functions like 'marketking…
|
CWE-862
Missing Authorization
|
CVE-2024-12413
|
2024-12-25 13:15 |
2024-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1875
|
8.8 |
HIGH
Network
|
-
|
-
|
The WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including,…
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2024-12272
|
2024-12-25 13:15 |
2024-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1876
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to unauthorized access of data due to a …
|
CWE-862
Missing Authorization
|
CVE-2024-12190
|
2024-12-25 13:15 |
2024-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1877
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Tourfic – Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking plugin for WordPress is vulnerable to SQL Injection via the 'enquiry_id' parameter of t…
|
CWE-89
SQL Injection
|
CVE-2024-12032
|
2024-12-25 13:15 |
2024-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1878
|
- |
|
-
|
-
|
A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar up to 2.9. Affected by this issue is some unknown functionality of the file /usuarios/tipos/2 of the compon…
|
-
|
CVE-2024-12893
|
2024-12-25 12:15 |
2024-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1879
|
- |
|
-
|
-
|
A vulnerability classified as problematic was found in code-projects Online Exam Mastering System 1.0. Affected by this vulnerability is an unknown functionality of the file /sign.php?q=account.php. …
|
-
|
CVE-2024-12892
|
2024-12-25 12:15 |
2024-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1880
|
- |
|
-
|
-
|
A vulnerability classified as critical has been found in code-projects Online Exam Mastering System 1.0. Affected is an unknown function of the file /account.php?q=quiz&step=2. The manipulation of th…
|
-
|
CVE-2024-12891
|
2024-12-25 12:15 |
2024-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|