High - CVE-2024-11740 - The The Download Manager plugin for WordPress...
The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.03. This is due to the software allowing users to execute an...
Medium - CVE-2024-11768 - The Download Manager plugin for WordPress is...
The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to improper password validation on the checkFilePassword function in all versions...
Medium - CVE-2024-12560 - The Button Block – Get fully customizable &...
The Button Block – Get fully customizable & multi-functional buttons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.5 via the...
NA - CVE-2020-12819 - A heap-based buffer overflow vulnerability in...
A heap-based buffer overflow vulnerability in the processing of Link Control Protocol messages in FortiGate versions 5.6.12, 6.0.10, 6.2.4 and 6.4.1 and earlier may allow a remote attacker with...
NA - CVE-2021-26093 - An access of uninitialized pointer (CWE-824)...
An access of uninitialized pointer (CWE-824) vulnerability in FortiWLC versions 8.6.0, 8.5.3 and earlier may allow a local and authenticated attacker to crash the access point being managed by the...
NA - CVE-2024-4229 - Incorrect Default Permissions vulnerability in...
Incorrect Default Permissions vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecross Basic Software for Developers versions 1.00 and later allows a malicious...
NA - CVE-2024-4230 - External Control of File Name or Path...
External Control of File Name or Path vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecross Basic Software for Developers versions 1.00 and later allows a...
NA - CVE-2024-12569 - Disclosure of sensitive information in...
Disclosure of sensitive information in HikVision camera driver's log file in XProtect Device Pack allows an attacker to read camera credentials stored in the Recording Server under specific...
NA - CVE-2023-4617 - Incorrect authorization vulnerability in HTTP...
Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android and iOS allows remote attacker to control devices owned by other users via changing "device", "sku"...
NA - CVE-2024-11616 - Netskope was made aware of a security...
Netskope was made aware of a security vulnerability in Netskope Endpoint DLP’s Content Control Driver where a double-fetch issue leads to heap overflow. The vulnerability arises from the fact that...