NA - CVE-2024-53688 - Improper neutralization of special elements...
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in AE1021 firmware versions 2.0.10 and earlier and AE1021PE firmware versions...
NA - CVE-2024-54457 - Inclusion of undocumented features or chicken...
Inclusion of undocumented features or chicken bits issue exists in AE1021 firmware versions 2.0.10 and earlier and AE1021PE firmware versions 2.0.10 and earlier, which may allow a logged-in user to...
NA - CVE-2024-11614 - An out-of-bounds read vulnerability was found...
An out-of-bounds read vulnerability was found in DPDK's Vhost library checksum offload feature. This issue enables an untrusted or compromised guest to crash the hypervisor's vSwitch by...
Medium - CVE-2024-12340 - The Animation Addons for Elementor plugin for...
The Animation Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.6 via the 'render' function in...
Medium - CVE-2024-12454 - The Affiliate Program Suite — SliceWP...
The Affiliate Program Suite — SliceWP Affiliates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.23. This is due to missing or incorrect...
Medium - CVE-2024-12554 - The Peter’s Custom Anti-Spam plugin for...
The Peter’s Custom Anti-Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.3. This is due to missing nonce validation on the...
Medium - CVE-2024-47104 - IBM i 7.4 and 7.5 is vulnerable to an...
IBM i 7.4 and 7.5 is vulnerable to an authenticated user gaining elevated privilege to a physical file. A user with authority to a view can alter the based-on physical file security attributes...
Medium - CVE-2024-11291 - The Paid Membership Subscriptions – Effortless...
The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and...
High - CVE-2024-11912 - The Travel Booking WordPress Theme theme for...
The Travel Booking WordPress Theme theme for WordPress is vulnerable to blind time-based SQL Injection via the ‘order_id’ parameter in all versions up to, and including, 3.1.6 due to insufficient...
Medium - CVE-2024-11926 - The Travel Booking WordPress Theme theme for...
The Travel Booking WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '__stPartnerCreateServiceRental',...