Medium - CVE-2024-12004 - The WPC Order Notes for WooCommerce plugin for...
The WPC Order Notes for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.2. This is due to missing or incorrect nonce...
Medium - CVE-2024-12283 - The WP Pipes plugin for WordPress is vulnerable...
The WP Pipes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘x1’ parameter in all versions up to, and including, 1.4.1 due to insufficient input sanitization and...
NA - CVE-2024-11401 - Rapid7 Insight Platform versions prior to...
Rapid7 Insight Platform versions prior to November 13th 2024, suffer from a privilege escalation vulnerability whereby, due to a lack of authorization checks, an attacker can successfully update...
NA - CVE-2024-11737 - CWE-20: Improper Input Validation vulnerability...
CWE-20: Improper Input Validation vulnerability exists that could lead to a denial of service and a loss of confidentiality, integrity of the controller when an unauthenticated crafted Modbus...
NA - CVE-2024-12363 - Insufficient permissions in the TeamViewer...
Insufficient permissions in the TeamViewer Patch & Asset Management component prior to version 24.12 on Windows allows a local authenticated user to delete arbitrary files. TeamViewer Patch & Asset...
NA - CVE-2024-54269 - Missing Authorization vulnerability in Ninja...
Missing Authorization vulnerability in Ninja Team Notibar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Notibar: from n/a through 2.1.4.
Medium - CVE-2024-11008 - The Members – Membership & User Role Editor...
The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.10 via the WordPress core search...
High - CVE-2024-11840 - The RapidLoad – Optimize Web Vitals...
The RapidLoad – Optimize Web Vitals Automatically plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the uucss_data,...
Medium - CVE-2024-12294 - The Last Viewed Posts by WPBeginner plugin for...
The Last Viewed Posts by WPBeginner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.1 via the 'get_legacy_cookies' function....
Medium - CVE-2024-12325 - The Waymark plugin for WordPress is vulnerable...
The Waymark plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, 1.4.1 due to insufficient input sanitization and...