Medium - CVE-2024-10705 - The Multiple Page Generator Plugin – MPG plugin...
The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.5 via the 'mpg_download_file_by_link'...
Medium - CVE-2024-11090 - The Membership Plugin – Restrict Content plugin...
The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.13 via the WordPress core search feature....
NA - CVE-2024-46881 - Develocity (formerly Gradle Enterprise) before...
Develocity (formerly Gradle Enterprise) before 2024.1.8 has Incorrect Access Control. Project-level access control configuration was introduced in Enterprise Config schema version 8. Migration...
High - CVE-2024-11641 - The VikBooking Hotel Booking Engine & PMS...
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.2. This is due to missing or incorrect nonce...
High - CVE-2024-11936 - The Zox News theme for WordPress is vulnerable...
The Zox News theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'backup_options' and...
Medium - CVE-2024-12334 - The WC Affiliate – A Complete WooCommerce...
The WC Affiliate – A Complete WooCommerce Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via any parameter in all versions up to, and including, 2.4 due to...
Medium - CVE-2024-13505 - The Survey Maker plugin for WordPress is...
The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ays_sections[5][questions][8][title]’ parameter in all versions up to, and including, 5.1.3.3 due to...
Medium - CVE-2023-38009 - IBM Cognos Mobile Client 1.1 iOS may be...
IBM Cognos Mobile Client 1.1 iOS may be vulnerable to information disclosure through man in the middle techniques due to the lack of certificate pinning.