Latest CVE Feed
-
8.8
HIGHCVE-2024-42582
A Cross-Site Request Forgery (CSRF) in the component delete_categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.... Read more
Affected Products : warehouse_inventory_system- Published: Aug. 20, 2024
- Modified: Aug. 21, 2024
-
8.8
HIGHCVE-2024-42583
A Cross-Site Request Forgery (CSRF) in the component delete_user.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.... Read more
Affected Products : warehouse_inventory_system- Published: Aug. 20, 2024
- Modified: Aug. 21, 2024
-
8.8
HIGHCVE-2024-42603
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=clearall... Read more
Affected Products : pligg_cms- Published: Aug. 20, 2024
- Modified: Aug. 21, 2024
-
8.8
HIGHCVE-2024-42605
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/edit_page.php?link_id=1... Read more
Affected Products : pligg_cms- Published: Aug. 20, 2024
- Modified: Aug. 21, 2024
-
8.8
HIGHCVE-2024-42606
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_log.php?clear=1... Read more
Affected Products : pligg_cms- Published: Aug. 20, 2024
- Modified: Aug. 21, 2024
-
8.8
HIGHCVE-2024-42607
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=database... Read more
Affected Products : pligg_cms- Published: Aug. 20, 2024
- Modified: Aug. 21, 2024
-
8.8
HIGHCVE-2024-42609
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=avatars... Read more
Affected Products : pligg_cms- Published: Aug. 20, 2024
- Modified: Aug. 21, 2024
-
8.8
HIGHCVE-2024-42610
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=files... Read more
Affected Products : pligg_cms- Published: Aug. 20, 2024
- Modified: Aug. 21, 2024
-
8.8
HIGHCVE-2024-42611
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/admin_page.php?link_id=1&mode=delete... Read more
Affected Products : pligg_cms- Published: Aug. 20, 2024
- Modified: Aug. 21, 2024
-
8.8
HIGHCVE-2024-42613
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_widgets.php?action=install&widget=akismet... Read more
Affected Products : pligg_cms- Published: Aug. 20, 2024
- Modified: Aug. 21, 2024
-
8.8
HIGHCVE-2024-42617
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_config.php?action=save&var_id=32... Read more
Affected Products : pligg_cms- Published: Aug. 20, 2024
- Modified: Aug. 21, 2024
-
8.8
HIGHCVE-2024-42618
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /module.php?module=karma... Read more
Affected Products : pligg_cms- Published: Aug. 20, 2024
- Modified: Aug. 21, 2024
-
8.8
HIGHCVE-2024-42621
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_editor.php... Read more
Affected Products : pligg_cms- Published: Aug. 20, 2024
- Modified: Aug. 21, 2024
-
7.5
HIGHCVE-2024-43380
fugit contains time tools for flor and the floraison group. The fugit "natural" parser, that turns "every wednesday at 5pm" into "0 17 * * 3", accepted any length of input and went on attempting to parse it, not returning promptly, as expected. The parse ... Read more
Affected Products : fugit- Published: Aug. 19, 2024
- Modified: Aug. 21, 2024
-
3.4
LOWCVE-2024-43379
TruffleHog is a secrets scanning tool. Prior to v3.81.9, this vulnerability allows a malicious actor to craft data in a way that, when scanned by specific detectors, could trigger the detector to make an unauthorized request to an endpoint chosen by the a... Read more
Affected Products : trufflehog- Published: Aug. 19, 2024
- Modified: Aug. 21, 2024
-
9.8
CRITICALCVE-2024-7921
A vulnerability has been found in Anhui Deshun Intelligent Technology Jieshun JieLink+ JSOTC2016 up to 20240805 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /report/ParkOutRecord/GetDataList. The ma... Read more
Affected Products : jielink\+_jsotc2016- Published: Aug. 19, 2024
- Modified: Aug. 21, 2024
-
9.8
CRITICALCVE-2024-44076
In Microcks before 1.10.0, the POST /api/import and POST /api/export endpoints allow non-administrator access.... Read more
Affected Products : microcks- Published: Aug. 19, 2024
- Modified: Aug. 21, 2024
-
9.8
CRITICALCVE-2024-7920
A vulnerability, which was classified as problematic, was found in Anhui Deshun Intelligent Technology Jieshun JieLink+ JSOTC2016 up to 20240805. Affected is an unknown function of the file /Report/ParkCommon/GetParkInThroughDeivces. The manipulation lead... Read more
Affected Products : jielink\+_jsotc2016- Published: Aug. 19, 2024
- Modified: Aug. 21, 2024
-
7.2
HIGHCVE-2024-7917
A vulnerability, which was classified as critical, has been found in DouPHP 1.7 Release 20220822. Affected by this issue is some unknown functionality of the file /admin/system.php of the component Favicon Handler. The manipulation of the argument site_fa... Read more
Affected Products : douphp- Published: Aug. 18, 2024
- Modified: Aug. 21, 2024
-
4.3
MEDIUMCVE-2024-5880
The Hide My Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2 due to the plugin not restricting access to the REST API when password protection is enabled. This makes it possible for unauth... Read more
Affected Products :- Published: Aug. 21, 2024
- Modified: Aug. 21, 2024