|
313681
|
9.8 |
CRITICAL
Network
|
ivanti
|
endpoint_manager
|
SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.
|
CWE-89
SQL Injection
|
CVE-2024-8191
|
2024-09-13 06:50 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313682
|
7.5 |
HIGH
Network
|
apollographql
|
apollo-router apollo_helms-charts_router apollo_router
|
The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Instances of the Apollo Router running versions >=…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2024-43783
|
2024-09-13 06:33 |
2024-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313683
|
7.5 |
HIGH
Network
|
apollographql
|
apollo_router apollo_helms-charts_router apollo-router apollo_query-planner apollo_gateway
|
Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Each team can own their slice of the graph independently, empowering them to deliver autonomously and incre…
|
CWE-674
Uncontrolled Recursion
|
CVE-2024-43414
|
2024-09-13 06:33 |
2024-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313684
|
5.4 |
MEDIUM
Network
|
wpmanageninja
|
ninja_tables
|
The Ninja Tables – Easiest Data Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.0.12 due to insufficient i…
|
CWE-79
Cross-site Scripting
|
CVE-2024-7304
|
2024-09-13 06:32 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313685
|
5.4 |
MEDIUM
Network
|
jegtheme
|
jeg_elementor_kit
|
The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.7 due to insufficient input sanitization and out…
|
CWE-79
Cross-site Scripting
|
CVE-2024-6804
|
2024-09-13 06:31 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313686
|
8.8 |
HIGH
Network
|
naiches
|
dark_mode_for_wp_dashboard
|
Cross-Site Request Forgery (CSRF) vulnerability in Naiche Dark Mode for WP Dashboard.This issue affects Dark Mode for WP Dashboard: from n/a through 1.2.3.
|
CWE-352
Origin Validation Error
|
CVE-2024-43325
|
2024-09-13 06:28 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313687
|
4.3 |
MEDIUM
Network
|
checkoutplugins
|
stripe_payments_for_woocommerce
|
Cross-Site Request Forgery (CSRF) vulnerability in Checkout Plugins Stripe Payments For WooCommerce by Checkout.This issue affects Stripe Payments For WooCommerce by Checkout: from n/a through 1.9.1.
|
CWE-352
Origin Validation Error
|
CVE-2024-43316
|
2024-09-13 06:26 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313688
|
5.4 |
MEDIUM
Network
|
fontsplugin
|
fonts_plugin
|
Cross-Site Request Forgery (CSRF) vulnerability in Fonts Plugin Fonts allows Stored XSS.This issue affects Fonts: from n/a through 3.7.7.
|
CWE-352
Origin Validation Error
|
CVE-2024-43301
|
2024-09-13 06:24 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313689
|
8.8 |
HIGH
Network
|
wpdeveloper
|
betterdocs
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper BetterDocs allows PHP Local File Inclusion.This issue affects BetterDocs: from n/a through …
|
CWE-22
Path Traversal
|
CVE-2024-43129
|
2024-09-13 06:21 |
2024-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313690
|
4.3 |
MEDIUM
Network
|
wpdataaccess
|
wp_data_access
|
Cross-Site Request Forgery (CSRF) vulnerability in Passionate Programmers B.V. WP Data Access.This issue affects WP Data Access: from n/a through 5.5.7.
|
CWE-352
Origin Validation Error
|
CVE-2024-43295
|
2024-09-13 06:20 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|