7.2
CVE-2022-2440 - Theme Editor <= 2.8 - Authenticated (Admin+) PHAR Deserialization
The Theme Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'images_array' parameter in versions up to, and including 2.8. This makes it possible for authenticated attackers with administrative privileges to call files using a PHAR wrapper that will deserializeβ¦
5.3
CVE-2024-5857 - Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor β Funnelforms Free <= β¦
The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor β Funnelforms Free plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the af2_handel_file_remove AJAX action in all versions up to, and including, 3.7.3.2. This makes iβ¦
3.1
CVE-2024-41918 -
'Rakuten Ichiba App' for Android 12.4.0 and earlier and 'Rakuten Ichiba App' for iOS 11.7.0 and earlier are vulnerable to improper authorization in handler for custom URL scheme. An arbitrary site may be displayed on the WebView of the product via Intent from another application installed on the usβ¦
6.5
CVE-2024-7857 - Media Library Folders <= 8.2.2 - Authenticated (Subscriber+) Second-Order SQL Injection
The Media Library Folders plugin for WordPress is vulnerable to second order SQL Injection via the 'sort_type' parameter of the 'mlf_change_sort_type' AJAX action in all versions up to, and including, 8.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparatiβ¦
6.5
CVE-2024-44930 -
Serilog before v2.1.0 was discovered to contain a Client IP Spoofing vulnerability, which allows attackers to falsify their IP addresses by specifying an arbitrary IP as a value of X-Forwarded-For or Client-Ip headers while performing HTTP requests.
6.1
CVE-2024-41350 -
bjyadmin commit a560fd5 is vulnerable to Cross Site Scripting (XSS) via Public/statics/umeditor1_2_3/php/imageUp.php
9.8
CVE-2024-45435 -
Chartist 1.x through 1.3.0 allows Prototype Pollution via the extend function.
9.8
CVE-2024-41367 -
RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\api\playlist\appendFileToPlaylist.php
9.8
CVE-2024-41370 -
Organizr v1.90 was discovered to contain a SQL injection vulnerability via chat/setlike.php.
9.1
CVE-2024-45436 -
extractFromZipFile in model.go in Ollama before 0.1.47 can extract members of a ZIP archive outside of the parent directory.