Medium - CVE-2024-7963 - The CMSMasters Content Composer plugin for...
The CMSMasters Content Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's multiple shortcodes in all versions up to, and including, 1.8.8 due to...
NA - CVE-2024-25282 - 3DSecure 2.0 allows XSS in its 3DSMethod...
3DSecure 2.0 allows XSS in its 3DSMethod Authentication via a modified params parameter in a /rest/online request with a /redirect?action=challenge&txn= substring.
NA - CVE-2024-25283 - 3DSecure 2.0 allows reflected XSS in the 3DS...
3DSecure 2.0 allows reflected XSS in the 3DS Authorization Challenge via a modified params parameter in a /rest/online request with a /redirect?action=challenge&txn= substring.
NA - CVE-2024-25285 - 3DSecure 2.0 allows form action hijacking via...
3DSecure 2.0 allows form action hijacking via threeDsMethod.jsp?threeDSMethodData= or the threeDSMethodNotificationURL parameter. The destination web site for a form submission can be modified.
NA - CVE-2024-35288 - Nitro PDF Pro before 13.70.8.82 and 14.x before...
Nitro PDF Pro before 13.70.8.82 and 14.x before 14.26.1.0 allows Local Privilege Escalation in the MSI Installer because custom actions occur unsafely in repair mode. CertUtil is run in a...
NA - CVE-2024-45179 - An issue was discovered in za-internet C-MOR...
An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to insufficient input validation, the C-MOR web interface is vulnerable to OS command injection attacks. It...
NA - CVE-2024-32608 - HDF5 library through 1.14.3 has memory...
HDF5 library through 1.14.3 has memory corruption in H5A__close resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.