Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-11-04 CVE-2024-51408 Server-Side Request Forgery (SSRF) vulnerability in Appsmith
AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to 169.254.169.254 to retrieve AWS metadata credentials.
network
low complexity
appsmith CWE-918
6.5
2024-11-04 CVE-2024-51582 Path Traversal vulnerability in Thimpress WP Hotel Booking
Path Traversal: '.../...//' vulnerability in ThimPress WP Hotel Booking allows PHP Local File Inclusion.This issue affects WP Hotel Booking: from n/a through 2.1.4.
network
low complexity
thimpress CWE-22
8.8
2024-11-04 CVE-2024-51665 Server-Side Request Forgery (SSRF) vulnerability in Wpthemespace Magical Addons for Elementor
Server-Side Request Forgery (SSRF) vulnerability in Noor alam Magical Addons For Elementor allows Server Side Request Forgery.This issue affects Magical Addons For Elementor: from n/a through 1.2.1.
network
low complexity
wpthemespace CWE-918
4.3
2024-11-04 CVE-2024-51672 SQL Injection vulnerability in Wpdeveloper Betterlinks
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPDeveloper BetterLinks allows SQL Injection.This issue affects BetterLinks: from n/a through 2.1.7.
network
low complexity
wpdeveloper CWE-89
7.2
2024-11-04 CVE-2024-51556 Use of a Broken or Risky Cryptographic Algorithm vulnerability in 63Moons Aero and Wave 2.0
This vulnerability exists in the Wave 2.0 due to insufficient encryption of sensitive data received at the API response.
network
low complexity
63moons CWE-327
6.5
2024-11-04 CVE-2024-51557 Allocation of Resources Without Limits or Throttling vulnerability in 63Moons Aero and Wave 2.0
This vulnerability exists in the Wave 2.0 due to missing rate limiting on OTP requests in an API endpoint.
network
low complexity
63moons CWE-770
6.5
2024-11-04 CVE-2024-51558 Improper Restriction of Excessive Authentication Attempts vulnerability in 63Moons Aero and Wave 2.0
This vulnerability exists in the Wave 2.0 due to missing restrictions for excessive failed authentication attempts on its API based login.
network
low complexity
63moons CWE-307
critical
9.8
2024-11-04 CVE-2024-51559 Unspecified vulnerability in 63Moons Aero and Wave 2.0
This vulnerability exists in the Wave 2.0 due to improper authorization checks on certain API endpoints.
network
low complexity
63moons
6.5
2024-11-04 CVE-2024-51560 Information Exposure Through an Error Message vulnerability in 63Moons Aero and Wave 2.0
This vulnerability exists in the Wave 2.0 due to improper exception handling for invalid inputs at certain API endpoint.
network
low complexity
63moons CWE-209
4.3
2024-11-04 CVE-2024-51561 Unspecified vulnerability in 63Moons Aero and Wave 2.0
This vulnerability exists in Aero due to improper implementation of OTP validation mechanism in certain API endpoints.
network
low complexity
63moons
7.5