Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-10-16 CVE-2024-9893 The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.1.14.
network
low complexity
CWE-288
critical
9.8
2024-10-16 CVE-2020-36841 The WooCommerce Smart Coupons plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the woocommerce_coupon_admin_init function in versions up to, and including, 4.6.0.
network
low complexity
CWE-285
5.3
2024-10-16 CVE-2024-10023 SQL Injection vulnerability in Code-Projects Pharmacy Management System 1.0
A vulnerability classified as critical was found in code-projects Pharmacy Management System 1.0.
network
low complexity
code-projects CWE-89
8.8
2024-10-16 CVE-2024-10024 SQL Injection vulnerability in Code-Projects Pharmacy Management System 1.0
A vulnerability, which was classified as critical, has been found in code-projects Pharmacy Management System 1.0.
network
low complexity
code-projects CWE-89
8.8
2024-10-16 CVE-2024-10021 SQL Injection vulnerability in Code-Projects Pharmacy Management System 1.0
A vulnerability was found in code-projects Pharmacy Management System 1.0.
network
low complexity
code-projects CWE-89
critical
9.8
2024-10-16 CVE-2024-10022 SQL Injection vulnerability in Code-Projects Pharmacy Management System 1.0
A vulnerability classified as critical has been found in code-projects Pharmacy Management System 1.0.
network
low complexity
code-projects CWE-89
critical
9.8
2024-10-16 CVE-2024-8921 The Zita Elementor Site Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6.3 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
6.4
2024-10-16 CVE-2024-9444 The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.4.3 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
6.4
2024-10-16 CVE-2016-15042 Unrestricted Upload of File with Dangerous Type vulnerability in Najeebmedia Frontend File Manager and Post Front-End Form
The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulnerable to arbitrary file uploads due to missing file type validation via the `nm_filemanager_upload_file` and `nm_postfront_upload_file` AJAX actions.
network
low complexity
najeebmedia CWE-434
critical
9.8
2024-10-16 CVE-2017-20193 Cross-site Scripting vulnerability in WOO Product Vendors
The Product Vendors is vulnerable to Reflected Cross-Site Scripting via the 'vendor_description' parameter in versions up to, and including, 2.0.35 due to insufficient input sanitization and output escaping.
network
low complexity
woo CWE-79
6.1