Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-10-05 CVE-2024-47390 Cross-site Scripting vulnerability in Jegtheme JEG Elementor KIT
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jegtheme Jeg Elementor Kit allows Stored XSS.This issue affects Jeg Elementor Kit: from n/a through 2.6.8.
network
low complexity
jegtheme CWE-79
5.4
2024-10-05 CVE-2024-47391 Cross-site Scripting vulnerability in Bold-Themes Bold Page Builder
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BoldThemes Bold Page Builder allows Stored XSS.This issue affects Bold Page Builder: from n/a before 5.1.1.
network
low complexity
bold-themes CWE-79
5.4
2024-10-05 CVE-2024-47392 Cross-site Scripting vulnerability in Bdthemes Element Pack
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BdThemes Element Pack Elementor Addons allows Stored XSS.This issue affects Element Pack Elementor Addons: from n/a through 5.7.5.
network
low complexity
bdthemes CWE-79
5.4
2024-10-05 CVE-2024-47625 Cross-site Scripting vulnerability in Themelooks Enter Addons
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemeLooks Enter Addons allows Stored XSS.This issue affects Enter Addons: from n/a through 2.1.8.
network
low complexity
themelooks CWE-79
5.4
2024-10-05 CVE-2024-9534 Classic Buffer Overflow vulnerability in Dlink Dir-605L Firmware 2.13B01
A vulnerability was found in D-Link DIR-605L 2.13B01 BETA.
network
low complexity
dlink CWE-120
8.8
2024-10-05 CVE-2024-9535 Classic Buffer Overflow vulnerability in Dlink Dir-605L Firmware 2.13B01
A vulnerability was found in D-Link DIR-605L 2.13B01 BETA.
network
low complexity
dlink CWE-120
8.8
2024-10-05 CVE-2024-9533 Classic Buffer Overflow vulnerability in Dlink Dir-605L Firmware 2.13B01
A vulnerability was found in D-Link DIR-605L 2.13B01 BETA and classified as critical.
network
low complexity
dlink CWE-120
8.8
2024-10-05 CVE-2024-9161 Missing Authorization vulnerability in Rankmath SEO
The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'update_metadata' function in all versions up to, and including, 1.0.228.
network
low complexity
rankmath CWE-862
6.5
2024-10-05 CVE-2024-9417 The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to limited file uploads due to a misconfigured file type validation in the 'handleUpload' function in all versions up to, and including, 1.1.9.
network
low complexity
CWE-434
6.1
2024-10-05 CVE-2024-8486 The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in the Modern Heading and Icon Picker widgets all versions up to, and including, 2.16.3 due to insufficient input sanitization and output escaping.
network
low complexity
6.4