301
|
- |
|
-
|
-
|
A JNDI injection issue was discovered in Cloudera JDBC Connector for Hive before 2.6.26 and JDBC Connector for Impala before 2.6.35. Attackers can inject malicious parameters into the JDBC URL, trigg…
|
-
|
CVE-2024-54660
|
2025-01-17 07:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
302
|
- |
|
-
|
-
|
An issue in Eugeny Tabby 1.0.213 allows a remote attacker to obtain sensitive information via the server and sends the SSH username and password even when the host key verification fails.
|
-
|
CVE-2024-48460
|
2025-01-17 07:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
303
|
- |
|
-
|
-
|
Incorrect access control in Tenda AC1200 Smart Dual-Band WiFi Router Model AC6 v2.0 Firmware v15.03.06.50 allows attackers to bypass authentication via a crafted web request.
|
-
|
CVE-2024-46450
|
2025-01-17 07:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
304
|
8.5 |
HIGH
Network
|
boldgrid
|
w3_total_cache
|
The W3 Total Cache plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is_w3tc_admin_page function in all versions up to, and including, 2.8.1. …
|
CWE-862
Missing Authorization
|
CVE-2024-12365
|
2025-01-17 06:31 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
305
|
7.5 |
HIGH
Network
boldgrid
|
w3_total_cache
|
The W3 Total Cache plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.8.1 through the publicly exposed debug log file. This makes it possible for unaut…
|
NVD-CWE-noinfo
|
CVE-2024-12008
|
2025-01-17 06:30 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
306
|
5.3 |
MEDIUM
Network
boldgrid
|
w3_total_cache
|
The W3 Total Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 2.8.1. This mak…
|
CWE-862
Missing Authorization
|
CVE-2024-12006
|
2025-01-17 06:30 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
307
|
5.4 |
MEDIUM
Network
|
themeisle
|
orbit_fox
|
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Table widget in all versions up to, and including, 2.10.43 due to insufficient in…
|
CWE-79
Cross-site Scripting
|
CVE-2025-0311
|
2025-01-17 06:29 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
308
|
5.4 |
MEDIUM
Network
|
themeisle
|
orbit_fox
|
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_tag’ parameter in all versions up to, and including, 2.10.43 due to insufficient input sani…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13183
|
2025-01-17 06:28 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
309
|
7.2 |
HIGH
Network
|
simple-help
|
simplehelp
|
SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to…
|
CWE-59
Link Following
|
CVE-2024-57728
|
2025-01-17 06:24 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
310
|
7.5 |
HIGH
Network
simple-help
|
simplehelp
|
SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleH…
|
CWE-22
Path Traversal
|
CVE-2024-57727
|
2025-01-17 06:22 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|