NA - CVE-2024-3506 - A possible buffer overflow in selected...
A possible buffer overflow in selected cameras' drivers from XProtect Device Pack can allow an attacker with access to internal network to execute commands on Recording Server under strict...
NA - CVE-2024-8422 - CWE-416: Use After Free vulnerability exists...
CWE-416: Use After Free vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when application user opens a malicious Zelio Soft...
Medium - CVE-2024-8433 - The Easy Mega Menu Plugin for WordPress –...
The Easy Mega Menu Plugin for WordPress – ThemeHunk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘themehunk_megamenu_bg_image' parameter in all versions up to, and...
NA - CVE-2024-8518 - CWE-20: Improper Input Validation vulnerability...
CWE-20: Improper Input Validation vulnerability exists that could cause a crash of the Zelio Soft 2 application when a specially crafted project file is loaded by an application user.
Medium - CVE-2024-8629 - The WooCommerce Multilingual & Multicurrency...
The WooCommerce Multilingual & Multicurrency with WPML plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL...
NA - CVE-2024-8488 - The Survey Maker plugin for WordPress is...
The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Survey fields in all versions up to, and including, 4.9.7 due to insufficient input sanitization and output...
NA - CVE-2024-8884 - CWE-200: Exposure of Sensitive Information to...
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause exposure of credentials when attacker has access to application on network over http
NA - CVE-2024-9005 - CWE-502: Deserialization of Untrusted Data...
CWE-502: Deserialization of Untrusted Data vulnerability exists that could allow code to be remotely executed on the server when unsafely deserialized data is posted to the web server.
Medium - CVE-2024-9207 - The BuddyPress Docs plugin for WordPress is...
The BuddyPress Docs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and...
Medium - CVE-2024-8431 - The Photo Gallery, Images, Slider in Rbs Image...
The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajaxGetGalleryJson() function in...