Aggregator
CVE-2024-10542 | CleanTalk Spam protection, Anti-Spam, Firewall Plugin up to 6.43.2 on WordPress Plugin Installation authorization
9 months 2 weeks ago
A vulnerability classified as problematic has been found in CleanTalk Spam protection, Anti-Spam, Firewall Plugin up to 6.43.2 on WordPress. This affects an unknown part of the component Plugin Installation Handler. The manipulation leads to authorization bypass.
This vulnerability is uniquely identified as CVE-2024-10542. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-11202 | CM Plugin on WordPress Shortcode cminds_free_guide cross site scripting
9 months 2 weeks ago
A vulnerability was found in CM Plugin on WordPress. It has been rated as problematic. Affected by this issue is the function cminds_free_guide of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-11202. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-11342 | Skt NURCaptcha Plugin up to 3.5.0 on WordPress cross site scripting
9 months 2 weeks ago
A vulnerability was found in Skt NURCaptcha Plugin up to 3.5.0 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-11342. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-9504 | Booking Calendar, Appointment Booking System Plugin SVG File Upload cross site scripting
9 months 2 weeks ago
A vulnerability was found in Booking Calendar, Appointment Booking System Plugin up to 3.2.15 on WordPress. It has been classified as problematic. Affected is an unknown function of the component SVG File Upload Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-9504. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-10781 | CleanTalk Spam protection, Anti-Spam, Firewall Plugin up to 6.44 on WordPress Plugin Installation authorization
9 months 2 weeks ago
A vulnerability was found in CleanTalk Spam protection, Anti-Spam, Firewall Plugin up to 6.44 on WordPress and classified as problematic. This issue affects some unknown processing of the component Plugin Installation Handler. The manipulation leads to authorization bypass.
The identification of this vulnerability is CVE-2024-10781. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-11002 | InPost Gallery Plugin up to 2.1.4.2 on WordPress Shortcode inpost_gallery_get_shortcode_template code injection
9 months 2 weeks ago
A vulnerability has been found in InPost Gallery Plugin up to 2.1.4.2 on WordPress and classified as critical. This vulnerability affects the function inpost_gallery_get_shortcode_template of the component Shortcode Handler. The manipulation leads to code injection.
This vulnerability was named CVE-2024-11002. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-10570 | CleanTalk Security & Malware Scan Plugin up to 2.145 on WordPress sql injection
9 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in CleanTalk Security & Malware Scan Plugin up to 2.145 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to sql injection.
This vulnerability is handled as CVE-2024-10570. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-10857 | Product Input Fields for WooCommerce Plugin up to 1.9 on WordPress path traversal
9 months 2 weeks ago
A vulnerability, which was classified as critical, was found in Product Input Fields for WooCommerce Plugin up to 1.9 on WordPress. This affects an unknown part. The manipulation leads to path traversal.
This vulnerability is uniquely identified as CVE-2024-10857. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-11418 | Additional Order Filters for WooCommerce Plugin up to 1.21 on WordPress cross site scripting
9 months 2 weeks ago
A vulnerability classified as problematic was found in Additional Order Filters for WooCommerce Plugin up to 1.21 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-11418. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-53261 | sveltejs kit up to 2.8.2 index.js cross site scripting
9 months 2 weeks ago
A vulnerability classified as problematic has been found in sveltejs kit up to 2.8.2. Affected is an unknown function of the file packages/kit/src/exports/vite/dev/index.js. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-53261. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-32468 | Deno up to 1.41.1 deno_doc search_index.js cross site scripting (GHSA-qqwr-j9mm-fhw6)
9 months 2 weeks ago
A vulnerability was found in Deno up to 1.41.1. It has been rated as problematic. This issue affects some unknown processing of the file search_index.js of the component deno_doc. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-32468. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-51723 | BlackBerry AtHoc 7.15 Management Console cross site scripting
9 months 2 weeks ago
A vulnerability was found in BlackBerry AtHoc 7.15. It has been declared as problematic. This vulnerability affects unknown code of the component Management Console. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-51723. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-52787 | libre-chat 0.0.6 upload_documents filename path traversal (ID 10)
9 months 2 weeks ago
A vulnerability was found in libre-chat 0.0.6. It has been classified as critical. This affects the function upload_documents. The manipulation of the argument filename leads to path traversal.
This vulnerability is uniquely identified as CVE-2024-52787. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-53599 | LafeLabs Chaos 0.0.1 /scroll.php cross site scripting
9 months 2 weeks ago
A vulnerability was found in LafeLabs Chaos 0.0.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /scroll.php. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-53599. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-53258 | Autolab download_all_submissions exposure of private personal information to an unauthorized actor (1aa4c769)
9 months 2 weeks ago
A vulnerability has been found in Autolab and classified as problematic. Affected by this vulnerability is the function download_all_submissions. The manipulation leads to exposure of private personal information to an unauthorized actor.
This vulnerability is known as CVE-2024-53258. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-53262 | sveltejs kit up to 2.8.2 error.html cross site scripting
9 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in sveltejs kit up to 2.8.2. Affected is an unknown function of the file error.html. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-53262. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-7915 | Sensei Mac Cleaner up to 1.5.10 XPC authorization
9 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in Sensei Mac Cleaner up to 1.5.10. This issue affects some unknown processing of the component XPC Handler. The manipulation leads to incorrect authorization.
The identification of this vulnerability is CVE-2024-7915. An attack has to be approached locally. There is no exploit available.
vuldb.com
CVE-2024-52811 | ngtcp2 = 1.9.0 conn_recv_pkt buffer overflow (GHSA-4gmv-gf46-r4g5)
9 months 2 weeks ago
A vulnerability classified as critical was found in ngtcp2 = 1.9.0. This vulnerability affects the function ngtcp2_conn::conn_recv_pkt. The manipulation leads to buffer overflow.
This vulnerability was named CVE-2024-52811. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-53255 | BoidCMS up to 2.1.1 /admin?page=media file cross site scripting (GHSA-7q7m-cgw8-px4r)
9 months 2 weeks ago
A vulnerability classified as problematic has been found in BoidCMS up to 2.1.1. This affects an unknown part of the file /admin?page=media. The manipulation of the argument file leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-53255. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com