Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In March 2024
Cross-Site Request Forgery (CSRF) vulnerability in GamiPress.This issue affects GamiPress: from n/a through 6.8.5.
CVSS Score
4.3
EPSS Score
0.002
Published
2024-03-29
Cross-Site Request Forgery (CSRF) vulnerability in VeronaLabs WP SMS.This issue affects WP SMS: from n/a through 6.6.2.
CVSS Score
4.3
EPSS Score
0.002
Published
2024-03-29
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks CRM Perks Forms allows Stored XSS.This issue affects CRM Perks Forms: from n/a through 1.1.4.
CVSS Score
6.5
EPSS Score
0.001
Published
2024-03-29
Dell OpenManage Enterprise, v4.0 and prior, contain(s) a path traversal vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, to gain unauthorized access to the files stored on the server filesystem, with the privileges of the running web application.
CVSS Score
5.7
EPSS Score
0.003
Published
2024-03-29
Tenda AC15V1.0 V15.03.20_multi has a command injection vulnerability via the deviceName parameter.
CVSS Score
8.0
EPSS Score
0.002
Published
2024-03-29
Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.2.
CVSS Score
6.5
EPSS Score
0.002
Published
2024-03-29
NextcloudPi is a ready to use image for Virtual Machines, Raspberry Pi, Odroid HC1, Rock64 and other boards. A command injection vulnerability in NextCloudPi allows command execution as the root user via the NextCloudPi web-panel. Due to a security misconfiguration this can be used by anyone with access to NextCloudPi web-panel, no authentication is required. It is recommended that the NextCloudPi is upgraded to 1.53.1.
CVSS Score
10.0
EPSS Score
0.01
Published
2024-03-29
Missing Authorization vulnerability in WPExperts Wholesale For WooCommerce.This issue affects Wholesale For WooCommerce: from n/a through 2.3.0.
CVSS Score
5.3
EPSS Score
0.002
Published
2024-03-29
Missing Authorization vulnerability in Klarna Klarna Payments for WooCommerce.This issue affects Klarna Payments for WooCommerce: from n/a through 3.2.4.
CVSS Score
5.3
EPSS Score
0.004
Published
2024-03-29
Cross-Site Request Forgery (CSRF) vulnerability in Brice CAPOBIANCO Simple Revisions Delete.This issue affects Simple Revisions Delete: from n/a through 1.5.3.
CVSS Score
4.3
EPSS Score
0.002
Published
2024-03-29


Contact Us

Shodan ® - All rights reserved