7.7
CVE-2023-3289 - A BOLA vulnerability in POST /services in EasyAppointments < 1.5.0
A BOLA vulnerability in POST /services allows a low privileged user to create a service for any user in the system (including admin). This results in unauthorized data manipulation.
5
CVE-2023-3290 - A BOLA vulnerability in POST /customers in EasyAppointments < 1.5.0
A BOLA vulnerability in POST /customers allows a low privileged user to create a low privileged user (customer) in the system. This results in unauthorized data manipulation.
9.9
CVE-2024-37424 - WordPress Newspack Blocks plugin <= 3.0.8 - Arbitrary File Upload vulnerability
Unrestricted Upload of File with Dangerous Type vulnerability in Automattic Newspack Blocks allows Upload a Web Shell to a Web Server.This issue affects Newspack Blocks: from n/a through 3.0.8.
7.7
CVE-2023-3286 - A BOLA vulnerability in POST /secretaries in EasyAppointments < 1.5.0
A BOLA vulnerability in POST /secretaries allows a low privileged user to create a low privileged user (secretary) in the system. This results in unauthorized data manipulation.
9.9
CVE-2024-37420 - WordPress Zita Elementor Site Library plugin <= 1.6.1 - Arbitrary Code Execution vulnerability
Unrestricted Upload of File with Dangerous Type vulnerability in WPZita Zita Elementor Site Library allows Upload a Web Shell to a Web Server.This issue affects Zita Elementor Site Library: from n/a through 1.6.1.
9.9
CVE-2023-3287 - A BOLA vulnerability in POST /admins in EasyAppointments < 1.5.0
A BOLA vulnerability in POST /admins allows a low privileged user to create a high privileged user (admin) in the system. This results in privilege escalation.
7.5
CVE-2024-37419 - WordPress Cowidgets โ Elementor Addons plugin <= 1.1.1 - Local File Inclusion vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Codeless Cowidgets โ Elementor Addons allows Path Traversal.This issue affects Cowidgets โ Elementor Addons: from n/a through 1.1.1.
0.0
CVE-2024-37418 - WordPress Church Admin plugin <= 4.4.6 - Arbitrary File Upload vulnerability
Unrestricted Upload of File with Dangerous Type vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.4.6.
7.2
CVE-2024-37410 - WordPress PowerPack Lite for Beaver Builder plugin <= 1.3.0.3 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in IdeaBox Creations PowerPack Lite for Beaver Builder powerpack-addon-for-beaver-builder.This issue affects PowerPack Lite for Beaver Builder: from n/a through <= 1.3.0.3.
8.5
CVE-2024-37268 - WordPress Striking theme <= 2.3.4 - Local File Inclusion vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in kaptinlin Striking allows Path Traversal.This issue affects Striking: from n/a through 2.3.4.