Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-10-20 CVE-2024-44000 Insufficiently Protected Credentials vulnerability in Litespeedtech Litespeed Cache
Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Authentication Bypass.This issue affects LiteSpeed Cache: from n/a before 6.5.0.1.
network
low complexity
litespeedtech CWE-522
critical
9.8
2024-10-20 CVE-2024-47634 Cross-Site Request Forgery (CSRF) vulnerability in Majas-Lapu-Izstrade Cartbounty
Cross-Site Request Forgery (CSRF) vulnerability in Streamline.Lv CartBounty – Save and recover abandoned carts for WooCommerce allows Cross Site Request Forgery.This issue affects CartBounty – Save and recover abandoned carts for WooCommerce: from n/a through 8.2.
network
low complexity
majas-lapu-izstrade CWE-352
critical
9.8
2024-10-20 CVE-2024-49250 Cross-Site Request Forgery (CSRF) vulnerability in Dublue Table of Contents Plus
Cross-Site Request Forgery (CSRF) vulnerability in Michael Tran Table of Contents Plus allows Cross Site Request Forgery.This issue affects Table of Contents Plus: from n/a through 2408.
network
low complexity
dublue CWE-352
8.8
2024-10-20 CVE-2024-49272 Cross-Site Request Forgery (CSRF) vulnerability in Wpwebinfotech Social Auto Poster
Cross-Site Request Forgery (CSRF) vulnerability in WPWeb Social Auto Poster allows Cross Site Request Forgery.This issue affects Social Auto Poster: from n/a through 5.3.15.
network
low complexity
wpwebinfotech CWE-352
8.8
2024-10-20 CVE-2024-49274 Cross-Site Request Forgery (CSRF) vulnerability in Infomaniak VOD Infomaniak
Cross-Site Request Forgery (CSRF) vulnerability in Infomaniak Staff VOD Infomaniak allows Cross Site Request Forgery.This issue affects VOD Infomaniak: from n/a through 1.5.7.
network
low complexity
infomaniak CWE-352
8.8
2024-10-20 CVE-2024-49275 Cross-Site Request Forgery (CSRF) vulnerability in Northernbeacheswebsites Ideapush
Cross-Site Request Forgery (CSRF) vulnerability in Martin Gibson IdeaPush allows Cross Site Request Forgery.This issue affects IdeaPush: from n/a through 8.69.
network
low complexity
northernbeacheswebsites CWE-352
8.8
2024-10-20 CVE-2024-49290 Cross-Site Request Forgery (CSRF) vulnerability in Boxystudio Cooked 1.7.5.6/1.7.5.7
Cross-Site Request Forgery (CSRF) vulnerability in Gora Tech LLC Cooked Pro allows Cross Site Request Forgery.This issue affects Cooked Pro: from n/a before 1.8.0.
network
low complexity
boxystudio CWE-352
8.8
2024-10-20 CVE-2024-49306 Cross-Site Request Forgery (CSRF) vulnerability in Wp-Buy WP Content Copy Protection & NO Right Click
Cross-Site Request Forgery (CSRF) vulnerability in WP-buy WP Content Copy Protection & No Right Click allows Cross Site Request Forgery.This issue affects WP Content Copy Protection & No Right Click: from n/a through 3.5.9.
network
low complexity
wp-buy CWE-352
8.8
2024-10-20 CVE-2024-49325 Missing Authorization vulnerability in Wpdiscover Photo Gallery Builder
Subscriber Broken Access Control in Photo Gallery Builder <= 3.0 versions.
network
low complexity
wpdiscover CWE-862
8.8
2024-10-20 CVE-2024-49627 Cross-Site Request Forgery (CSRF) vulnerability in Noorsplugin Wordpress Image SEO
Cross-Site Request Forgery (CSRF) vulnerability in Noor Alam WordPress Image SEO allows Cross Site Request Forgery.This issue affects WordPress Image SEO: from n/a through 1.1.4.
network
low complexity
noorsplugin CWE-352
8.8