|
313391
|
8.8 |
HIGH
Network
|
thimpress
|
learnpress
|
Cross-Site Request Forgery (CSRF) vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.6.8.2.
|
CWE-352
Origin Validation Error
|
CVE-2024-39641
|
2024-09-19 01:57 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313392
|
8.8 |
HIGH
Network
|
themeum
|
tutor_lms
|
Cross-Site Request Forgery (CSRF) vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.7.2.
|
CWE-352
Origin Validation Error
|
CVE-2024-39645
|
2024-09-19 01:46 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313393
|
8.8 |
HIGH
Network
|
sender
|
sender
|
Cross-Site Request Forgery (CSRF) vulnerability in Sender Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce.This issue affects Sender – Newsletter, SMS and Email Marketing Autom…
|
CWE-352
Origin Validation Error
|
CVE-2024-39657
|
2024-09-19 01:25 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313394
|
8.8 |
HIGH
Network
|
10up
|
simple_local_avatars
|
Cross-Site Request Forgery (CSRF) vulnerability in 10up Simple Local Avatars.This issue affects Simple Local Avatars: from n/a through 2.7.10.
|
CWE-352
Origin Validation Error
|
CVE-2024-43116
|
2024-09-19 01:22 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313395
|
8.8 |
HIGH
Network
|
loftware
|
spectrum
|
Loftware Spectrum before 4.6 HF14 allows authenticated XXE attacks.
|
CWE-611
XXE
|
CVE-2023-37233
|
2024-09-19 01:10 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313396
|
9.8 |
CRITICAL
Network
|
loftware
|
spectrum
|
Loftware Spectrum through 4.6 has unprotected JMX Registry.
|
NVD-CWE-noinfo
|
CVE-2023-37234
|
2024-09-19 01:05 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313397
|
7.5 |
HIGH
Network
|
loftware
|
spectrum
|
Loftware Spectrum through 4.6 exposes Sensitive Information (Logs) to an Unauthorized Actor.
|
NVD-CWE-noinfo
|
CVE-2023-37232
|
2024-09-19 00:55 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313398
|
8.8 |
HIGH
Network
|
inspireui
|
mstore_api
|
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_user_profile() function i…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-8242
|
2024-09-19 00:47 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313399
|
9.1 |
CRITICAL
Network
|
siemens
|
simatic_rf360r_firmware simatic_rf1170r_firmware simatic_rf1140r_firmware simatic_reader_rf685r_fcc_firmware simatic_reader_rf685r_etsi_firmware simatic_reader_rf685r_cmiit_firmware
|
A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC Reader RF…
|
NVD-CWE-noinfo
|
CVE-2024-37995
|
2024-09-19 00:37 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313400
|
7.1 |
HIGH
Network
|
siemens
|
simatic_rf360r_firmware simatic_rf1170r_firmware simatic_rf1140r_firmware simatic_reader_rf685r_fcc_firmware simatic_reader_rf685r_etsi_firmware simatic_reader_rf685r_cmiit_firmware
|
A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC Reader RF…
|
NVD-CWE-Other
|
CVE-2024-37994
|
2024-09-19 00:35 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|