Export limit exceeded: 358905 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (358905 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2024-31423 | 2 Alex Volkov, Volkov | 2 Wp Accessibility Helper, Wp Accessibility Helper | 2024-11-21 | 4.3 Medium |
| Missing Authorization vulnerability in Alex Volkov WP Accessibility Helper (WAH).This issue affects WP Accessibility Helper (WAH): from n/a through 0.6.2.5. | ||||
| CVE-2024-31411 | 1 Apache | 1 Streampipes | 2024-11-21 | 8.8 High |
| Unrestricted Upload of File with dangerous type vulnerability in Apache StreamPipes. Such a dangerous type might be an executable file that may lead to a remote code execution (RCE). The unrestricted upload is only possible for authenticated and authorized users. This issue affects Apache StreamPipes: through 0.93.0. Users are recommended to upgrade to version 0.95.0, which fixes the issue. | ||||
| CVE-2024-31294 | 1 Androidbubble | 1 Wp Sort Order | 2024-11-21 | 4.3 Medium |
| Missing Authorization vulnerability in Fahad Mahmood WP Sort Order.This issue affects WP Sort Order: from n/a through 1.3.1. | ||||
| CVE-2024-31284 | 1 Wpdeveloper | 1 Embedpress | 2024-11-21 | 6.5 Medium |
| Missing Authorization vulnerability in WPDeveloper EmbedPress.This issue affects EmbedPress: from n/a through 3.9.8. | ||||
| CVE-2024-31283 | 1 Zorem | 1 Advanced Local Pickup For Woocommerce | 2024-11-21 | 7.5 High |
| Missing Authorization vulnerability in zorem Advanced Local Pickup for WooCommerce.This issue affects Advanced Local Pickup for WooCommerce: from n/a through 1.6.2. | ||||
| CVE-2024-31276 | 1 Wpfactory | 1 Products\, Order \& Customers Export For Woocommerce | 2024-11-21 | 5.3 Medium |
| Missing Authorization vulnerability in WPFactory Products, Order & Customers Export for WooCommerce.This issue affects Products, Order & Customers Export for WooCommerce: from n/a through 2.0.8. | ||||
| CVE-2024-31275 | 1 Metagauss | 1 Eventprime | 2024-11-21 | 8.2 High |
| Missing Authorization vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.4. | ||||
| CVE-2024-31274 | 1 Wpdeveloper | 1 Embedpress | 2024-11-21 | 5.3 Medium |
| Missing Authorization vulnerability in WPDeveloper EmbedPress.This issue affects EmbedPress: from n/a through 3.9.11. | ||||
| CVE-2024-31273 | 1 Wiselyhub | 1 Js Help Desk | 2024-11-21 | 5.3 Medium |
| Missing Authorization vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.8.3. | ||||
| CVE-2024-31267 | 1 Wpdesk | 1 Flexible Checkout Fields | 2024-11-21 | 4.3 Medium |
| Missing Authorization vulnerability in WP Desk Flexible Checkout Fields for WooCommerce.This issue affects Flexible Checkout Fields for WooCommerce: from n/a through 4.1.2. | ||||
| CVE-2024-31244 | 1 Bricksforge | 1 Bricksforge | 2024-11-21 | 9.8 Critical |
| Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17. | ||||
| CVE-2024-31243 | 1 Bricksforge | 1 Bricksforge | 2024-11-21 | 7.5 High |
| Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17. | ||||
| CVE-2024-31217 | 1 Strapi | 1 Strapi | 2024-11-21 | 5.3 Medium |
| Strapi is an open-source content management system. Prior to version 4.22.0, a denial-of-service vulnerability is present in the media upload process causing the server to crash without restarting, affecting either development and production environments. Usually, errors in the application cause it to log the error and keep it running for other clients. This behavior, in contrast, stops the server execution, making it unavailable for any clients until it's manually restarted. Any user with access to the file upload functionality is able to exploit this vulnerability, affecting applications running in both development mode and production mode as well. Users should upgrade @strapi/plugin-upload to version 4.22.0 to receive a patch. | ||||
| CVE-2024-31161 | 1 Asus | 1 Download Master | 2024-11-21 | 7.2 High |
| The upload functionality of ASUS Download Master does not properly filter user input. Remote attackers with administrative privilege can exploit this vulnerability to upload any file to any location. They may even upload malicious web page files to the website directory, allowing arbitrary system commands to be executed upon browsing the webpage. | ||||
| CVE-2024-31160 | 1 Asus | 1 Download Master | 2024-11-21 | 4.8 Medium |
| The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacker with administrative privilege can insert JavaScript code to the parameter for Stored Cross-site scripting attacks. | ||||
| CVE-2024-31159 | 1 Asus | 1 Download Master | 2024-11-21 | 4.8 Medium |
| The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacker with administrative privilege can insert JavaScript code to the parameter for Reflected Cross-site scripting attacks. | ||||
| CVE-2024-31152 | 2 Level1, Levelone | 3 Wbr-6012, Wbr-6012 Firmware, Wbr-6012 | 2024-11-21 | 5.3 Medium |
| The LevelOne WBR-6012 router with firmware R0.40e6 is vulnerable to improper resource allocation within its web application, where a series of crafted HTTP requests can cause a reboot. This could lead to network service interruptions. | ||||
| CVE-2024-31138 | 1 Jetbrains | 1 Teamcity | 2024-11-21 | 4.6 Medium |
| In JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settings | ||||
| CVE-2024-31137 | 1 Jetbrains | 1 Teamcity | 2024-11-21 | 6.8 Medium |
| In JetBrains TeamCity before 2024.03 reflected XSS was possible via Space connection configuration | ||||
| CVE-2024-31135 | 1 Jetbrains | 1 Teamcity | 2024-11-21 | 6.1 Medium |
| In JetBrains TeamCity before 2024.03 open redirect was possible on the login page | ||||