Medium - CVE-2023-1419 - A script injection vulnerability was found in...
A script injection vulnerability was found in the Debezium database connector, where it does not properly sanitize some parameters. This flaw allows an attacker to send a malicious request to...
High - CVE-2023-4639 - A flaw was found in Undertow, which incorrectly...
A flaw was found in Undertow, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to...
Medium - CVE-2023-6110 - A flaw was found in OpenStack. When a user...
A flaw was found in OpenStack. When a user tries to delete a non-existing access rule in it's scope, it deletes other existing access rules which are not associated with any application...
High - CVE-2024-0793 - A flaw was found in kube-controller-manager....
A flaw was found in kube-controller-manager. This issue occurs when the initial application of a HPA config YAML lacking a .spec.behavior.scaleUp block causes a denial of service due to KCM pods...
NA - CVE-2023-43091 - A flaw was found in GNOME Maps, which is...
A flaw was found in GNOME Maps, which is vulnerable to a code injection attack via its service.json configuration file. If the configuration file is malicious, it may execute arbitrary code.
Medium - CVE-2024-10786 - The Simple Local Avatars plugin for WordPress...
The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capability check on the sla_clear_user_cache function in all versions up to, and...
Medium - CVE-2024-10795 - The Popularis Extra plugin for WordPress is...
The Popularis Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.7 via the 'elementor-template' shortcode due to insufficient...
Medium - CVE-2024-10861 - The Popup Box – Create Countdown, Coupon,...
The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the...
Medium - CVE-2024-10015 - The ConvertCalculator for WordPress plugin for...
The ConvertCalculator for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' and 'type' parameters in all versions up to, and including,...
Medium - CVE-2024-10017 - The PJW Mime Config plugin for WordPress is...
The PJW Mime Config plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0 due to insufficient input sanitization and...