2131
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Reactflow Visitor Recording and Heatmaps plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.10. This is due to missing or incorrect nonce v…
|
CWE-352
Origin Validation Error
|
CVE-2024-11975
|
2024-12-21 16:15 |
2024-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2132
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The One Click Upsell Funnel for WooCommerce – Funnel Builder for WordPress, Create WooCommerce Upsell, Post-Purchase Upsell & Cross Sell Offers that Boost Sales & Increase Profits with Sales Funnel …
|
CWE-79
Cross-site Scripting
|
CVE-2024-11938
|
2024-12-21 16:15 |
2024-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2133
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The G Web Pro Store Locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'q' parameter in all versions up to, and including, 2.1 due to insufficient input sanitization…
|
CWE-79
Cross-site Scripting
|
CVE-2024-11682
|
2024-12-21 16:15 |
2024-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2134
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Ebook Store plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 5.80…
|
CWE-79
Cross-site Scripting
|
CVE-2024-11287
|
2024-12-21 16:15 |
2024-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2135
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Multi-column Tag Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mctagmap shortcode in all versions up to, and including, 17.0.33 due to insufficient input …
|
CWE-79
Cross-site Scripting
|
CVE-2024-11196
|
2024-12-21 16:15 |
2024-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2136
|
7.3 |
HIGH
Network
-
|
-
|
The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.4.10. This is due to the softw…
|
CWE-94
Code Injection
|
CVE-2024-11977
|
2024-12-21 15:15 |
2024-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2137
|
- |
|
-
|
-
|
A vulnerability, which was classified as problematic, has been found in Emlog Pro up to 2.4.1. Affected by this issue is some unknown functionality of the file /admin/link.php. The manipulation of th…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2024-12846
|
2024-12-21 14:15 |
2024-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2138
|
9.8 |
CRITICAL
Network
-
|
-
|
The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.6. This is due to the plugin not properly verifying a user's identity prior to authen…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2024-11349
|
2024-12-21 14:15 |
2024-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2139
|
- |
|
-
|
-
|
An AirVantage online Warranty Checker tool vulnerability could allow an attacker to
perform bulk enumeration of IMEI and Serial Numbers pairs. The AirVantage Warranty Checker is updated to no longer…
|
-
|
CVE-2023-31280
|
2024-12-21 09:15 |
2024-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2140
|
- |
|
-
|
-
|
The AirVantage platform is vulnerable to an unauthorized attacker registering previously unregistered
devices on the AirVantage platform when the owner has not disabled the AirVantage Management
Se…
|
-
|
CVE-2023-31279
|
2024-12-21 09:15 |
2024-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|