VulDB Updates Updates
- CVE-2024-12771 | eCommerce Product Catalog Plugin up to 3.3.43 on WordPress Password Reset cross-site request forgeryby vuldb.com on December 21, 2024 at 7:28 am
A vulnerability classified as problematic has been found in eCommerce Product Catalog Plugin up to 3.3.43 on WordPress. This affects an unknown part of the component Password Reset Handler. The manipulation leads to cross-site request forgery. This vulnerability is uniquely identified as CVE-2024-12771. It is possible to initiate the attack remotely. There is no exploit available.
- CVE-2024-12066 | SMSA Shipping Plugin up to 2.2 on WordPress File file inclusionby vuldb.com on December 21, 2024 at 7:28 am
A vulnerability was found in SMSA Shipping Plugin up to 2.2 on WordPress and classified as critical. Affected by this issue is some unknown functionality of the component File Handler. The manipulation leads to file inclusion. This vulnerability is handled as CVE-2024-12066. The attack may be launched remotely. There is no exploit available.
- CVE-2024-12635 | WP Docs Plugin up to 2.2.0 on WordPress dir_id sql injectionby vuldb.com on December 21, 2024 at 7:28 am
A vulnerability has been found in WP Docs Plugin up to 2.2.0 on WordPress and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation of the argument dir_id leads to sql injection. This vulnerability is known as CVE-2024-12635. The attack can be launched remotely. There is no exploit available.
- CVE-2024-11682 | G Web Pro Store Locator Plugin up to 2.1 on WordPress cross site scriptingby vuldb.com on December 21, 2024 at 7:28 am
A vulnerability was found in G Web Pro Store Locator Plugin up to 2.1 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting. This vulnerability was named CVE-2024-11682. The attack can be initiated remotely. There is no exploit available.
- CVE-2024-11938 | One Click Upsell Funnel Plugin up to 3.4.9 on WordPress Shortcode wps_wocuf_pro_yes cross site scriptingby vuldb.com on December 21, 2024 at 7:28 am
A vulnerability was found in One Click Upsell Funnel Plugin up to 3.4.9 on WordPress. It has been classified as problematic. This affects the function wps_wocuf_pro_yes of the component Shortcode Handler. The manipulation leads to cross site scripting. This vulnerability is uniquely identified as CVE-2024-11938. It is possible to initiate the attack remotely. There is no exploit available.
- CVE-2024-12697 | real.Kit Plugin up to 5.1.1 on WordPress cross site scriptingby vuldb.com on December 21, 2024 at 7:28 am
A vulnerability was found in real.Kit Plugin up to 5.1.1 on WordPress. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting. The identification of this vulnerability is CVE-2024-12697. The attack may be initiated remotely. There is no exploit available.
- CVE-2024-12262 | Ebook Store Plugin up to 5.8001 on WordPress step cross site scriptingby vuldb.com on December 21, 2024 at 7:28 am
A vulnerability classified as problematic has been found in Ebook Store Plugin up to 5.8001 on WordPress. Affected is an unknown function. The manipulation of the argument step leads to cross site scripting. This vulnerability is traded as CVE-2024-12262. It is possible to launch the attack remotely. There is no exploit available.
- CVE-2024-11287 | Ebook Store Plugin up to 5.8001 on WordPress cross site scriptingby vuldb.com on December 21, 2024 at 7:28 am
A vulnerability classified as problematic was found in Ebook Store Plugin up to 5.8001 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting. This vulnerability is known as CVE-2024-11287. The attack can be launched remotely. There is no exploit available.
- CVE-2024-12721 | Custom Product Tabs for WooCommerce Plugin up to 1.2.4 on WordPress code injectionby vuldb.com on December 21, 2024 at 7:28 am
A vulnerability was found in Custom Product Tabs for WooCommerce Plugin up to 1.2.4 on WordPress. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to code injection. This vulnerability is handled as CVE-2024-12721. The attack may be launched remotely. There is no exploit available.
- CVE-2024-11196 | Multi-column Tag Map Plugin up to 17.0.33 on WordPress Shortcode mctagmap cross site scriptingby vuldb.com on December 21, 2024 at 7:28 am
A vulnerability, which was classified as problematic, has been found in Multi-column Tag Map Plugin up to 17.0.33 on WordPress. Affected by this issue is the function mctagmap of the component Shortcode Handler. The manipulation leads to cross site scripting. This vulnerability is handled as CVE-2024-11196. The attack may be launched remotely. There is no exploit available.
- CVE-2024-11975 | Reactflow Visitor Recording and Heatmaps Plugin up to 1.0.10 on WordPress cross-site request forgeryby vuldb.com on December 21, 2024 at 7:28 am
A vulnerability was found in Reactflow Visitor Recording and Heatmaps Plugin up to 1.0.10 on WordPress. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery. This vulnerability is traded as CVE-2024-11975. It is possible to launch the attack remotely. There is no exploit available.
- CVE-2010-4300 | Wireshark up to 1.4.1 packet-ldss.c dissect_ldss_transfer memory corruption (Bug 5318 / EDB-15676)by vuldb.com on December 21, 2024 at 7:18 am
A vulnerability classified as critical has been found in Wireshark up to 1.4.1. This affects the function dissect_ldss_transfer of the file epan/dissectors/packet-ldss.c. The manipulation leads to memory corruption. This vulnerability is uniquely identified as CVE-2010-4300. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
- CVE-2009-3525 | Linux Foundation Xen 3.0.3/3.3.0/3.3.1 grub.conf access control (Bug 525740# / EDB-33255)by vuldb.com on December 21, 2024 at 7:07 am
A vulnerability classified as critical was found in Linux Foundation Xen 3.0.3/3.3.0/3.3.1. This vulnerability affects unknown code of the file grub.conf. The manipulation leads to improper access controls. This vulnerability was named CVE-2009-3525. An attack has to be approached locally. Furthermore, there is an exploit available.
- CVE-2002-0741 | Psychoid psyBNC 2.3 PASS Command password denial of service (EDB-383 / XFDB-8912)by vuldb.com on December 21, 2024 at 7:00 am
A vulnerability was found in Psychoid psyBNC 2.3. It has been classified as problematic. This affects an unknown part of the component PASS Command Handler. The manipulation of the argument password leads to denial of service. This vulnerability is uniquely identified as CVE-2002-0741. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
- CVE-2011-5040 | Infoproject Biznis Heroj nalozi_naslov.php config cross site scripting (EDB-18259 / XFDB-71928)by vuldb.com on December 21, 2024 at 6:52 am
A vulnerability was found in Infoproject Biznis Heroj and classified as problematic. This issue affects some unknown processing of the file nalozi_naslov.php. The manipulation of the argument config leads to cross site scripting. The identification of this vulnerability is CVE-2011-5040. The attack may be initiated remotely. Furthermore, there is an exploit available.
- CVE-2003-1386 | AXIS 2401 Video Server up to 2.33 HTTP Request /support/messages access control (EDB-22296 / Nessus ID 11298)by vuldb.com on December 21, 2024 at 6:44 am
A vulnerability has been found in AXIS 2401 Video Server up to 2.33 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /support/messages of the component HTTP Request Handler. The manipulation leads to improper access controls. This vulnerability is known as CVE-2003-1386. The attack can be launched remotely. Furthermore, there is an exploit available.
- CVE-2013-2261 | Cryptocat Extension up to 2.0.21 on Chrome img/keygen.gif information disclosure (EDB-38636 / BID-61090)by vuldb.com on December 21, 2024 at 6:35 am
A vulnerability was found in Cryptocat Extension up to 2.0.21 on Chrome. It has been declared as problematic. This vulnerability affects unknown code of the file img/keygen.gif. The manipulation leads to information disclosure. This vulnerability was named CVE-2013-2261. The attack can be initiated remotely. Furthermore, there is an exploit available. It is recommended to upgrade the affected component.
- CVE-2024-11977 | kk Star Ratings Plugin up to 5.4.10 on WordPress Shortcode code injectionby vuldb.com on December 21, 2024 at 6:27 am
A vulnerability, which was classified as critical, has been found in kk Star Ratings Plugin up to 5.4.10 on WordPress. This issue affects some unknown processing of the component Shortcode Handler. The manipulation leads to code injection. The identification of this vulnerability is CVE-2024-11977. The attack may be initiated remotely. There is no exploit available.
- CVE-2014-0114 | Oracle Primavera Contract Management 13.1/14.0 Web Access commons-beanutils-1.8.0.jar this input validation (EDB-41690 / Nessus ID 73922)by vuldb.com on December 21, 2024 at 6:19 am
A vulnerability, which was classified as critical, was found in Oracle Primavera Contract Management 13.1/14.0. This affects an unknown part in the library lib/commons-beanutils-1.8.0.jar of the component Web Access. The manipulation of the argument this leads to improper input validation. This vulnerability is uniquely identified as CVE-2014-0114. It is possible to initiate the attack remotely. Furthermore, there is an exploit available. It is recommended to upgrade the affected component.
- CVE-2001-0520 | Aladdin eSafe Gateway up to 3.0 Filter privileges management (EDB-20869 / XFDB-6580)by vuldb.com on December 21, 2024 at 6:09 am
A vulnerability has been found in Aladdin eSafe Gateway up to 3.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Filter. The manipulation leads to improper privilege management. This vulnerability is known as CVE-2001-0520. The attack can be launched remotely. Furthermore, there is an exploit available.
- CVE-2005-3358 | Linux Kernel up to 2.6.15 kTwinHan DST Frontend/Card memory corruption (EDB-27031 / Nessus ID 21977)by vuldb.com on December 21, 2024 at 6:00 am
A vulnerability classified as problematic was found in Linux Kernel up to 2.6.15. Affected by this vulnerability is an unknown functionality of the component kTwinHan DST Frontend/Card. The manipulation leads to memory corruption. This vulnerability is known as CVE-2005-3358. Access to the local network is required for this attack to succeed. Furthermore, there is an exploit available. It is recommended to upgrade the affected component.
- CVE-2002-0386 | Oracle Application Server 9.0.2 Administration Module denial of service (EDB-21911 / Nessus ID 11076)by vuldb.com on December 21, 2024 at 5:52 am
A vulnerability, which was classified as problematic, has been found in Oracle Application Server 9.0.2. Affected by this issue is some unknown functionality of the component Administration Module. The manipulation leads to denial of service. This vulnerability is handled as CVE-2002-0386. The attack may be launched remotely. Furthermore, there is an exploit available. It is recommended to upgrade the affected component.
- CVE-2015-5092 | Adobe Acrobat Reader up to 10.1.14/11.0.11 information disclosure (APSB15-15 / Nessus ID 84800)by vuldb.com on December 21, 2024 at 5:44 am
A vulnerability classified as critical was found in Adobe Acrobat Reader up to 10.1.14/11.0.11. Affected by this vulnerability is an unknown functionality. The manipulation leads to information disclosure. This vulnerability is known as CVE-2015-5092. The attack can be launched remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2015-5093 | Adobe Acrobat Reader up to 10.1.14/11.0.11 memory corruption (APSB15-15 / Nessus ID 84800)by vuldb.com on December 21, 2024 at 5:44 am
A vulnerability, which was classified as critical, has been found in Adobe Acrobat Reader up to 10.1.14/11.0.11. Affected by this issue is some unknown functionality. The manipulation leads to memory corruption. This vulnerability is handled as CVE-2015-5093. The attack may be launched remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2015-5094 | Adobe Acrobat Reader up to 10.1.14/11.0.11 memory corruption (APSB15-15 / Nessus ID 84800)by vuldb.com on December 21, 2024 at 5:44 am
A vulnerability, which was classified as critical, was found in Adobe Acrobat Reader up to 10.1.14/11.0.11. This affects an unknown part. The manipulation leads to memory corruption. This vulnerability is uniquely identified as CVE-2015-5094. It is possible to initiate the attack remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2015-5091 | Adobe Acrobat Reader up to 10.1.14/11.0.11 input validation (APSB15-15 / Nessus ID 84800)by vuldb.com on December 21, 2024 at 5:44 am
A vulnerability classified as problematic has been found in Adobe Acrobat Reader up to 10.1.14/11.0.11. Affected is an unknown function. The manipulation leads to improper input validation. This vulnerability is traded as CVE-2015-5091. It is possible to launch the attack remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2015-5087 | Adobe Acrobat Reader up to 10.1.14/11.0.11 memory corruption (APSB15-15 / Nessus ID 84800)by vuldb.com on December 21, 2024 at 5:44 am
A vulnerability was found in Adobe Acrobat Reader up to 10.1.14/11.0.11 and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to memory corruption. This vulnerability is handled as CVE-2015-5087. The attack may be launched remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2015-5089 | Adobe Acrobat Reader up to 10.1.14/11.0.11 information disclosure (APSB15-15 / Nessus ID 84800)by vuldb.com on December 21, 2024 at 5:44 am
A vulnerability was found in Adobe Acrobat Reader up to 10.1.14/11.0.11. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to information disclosure. This vulnerability was named CVE-2015-5089. The attack can be initiated remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2015-5088 | Adobe Acrobat Reader up to 10.1.14/11.0.11 information disclosure (APSB15-15 / Nessus ID 84800)by vuldb.com on December 21, 2024 at 5:44 am
A vulnerability was found in Adobe Acrobat Reader up to 10.1.14/11.0.11. It has been classified as critical. This affects an unknown part. The manipulation leads to information disclosure. This vulnerability is uniquely identified as CVE-2015-5088. It is possible to initiate the attack remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2015-5090 | Adobe Acrobat Reader up to 10.1.14/11.0.11 access control (APSB15-15 / Nessus ID 84800)by vuldb.com on December 21, 2024 at 5:44 am
A vulnerability was found in Adobe Acrobat Reader up to 10.1.14/11.0.11. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to improper access controls. The identification of this vulnerability is CVE-2015-5090. The attack may be initiated remotely. There is no exploit available. It is recommended to upgrade the affected component.