NA - CVE-2024-45068 - Authentication credentials leakage...
Authentication credentials leakage vulnerability in Hitachi Ops Center Common Services within Hitachi Ops Center OVA. This issue affects Hitachi Ops Center Common Services: from 10.9.3-00 before...
Medium - CVE-2024-9694 - The CMSMasters Elementor Addon plugin for...
The CMSMasters Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.14.7 due to insufficient input...
Medium - CVE-2024-10484 - The Spectra – WordPress Gutenberg Blocks plugin...
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Team' widget in all versions up to, and including, 2.16.2...
NA - CVE-2024-10893 - The WP Booking Calendar WordPress plugin before...
The WP Booking Calendar WordPress plugin before 10.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting...
NA - CVE-2024-49411 - Path Traversal in ThemeCenter prior to SMR...
Path Traversal in ThemeCenter prior to SMR Dec-2024 Release 1 allows physical attackers to copy apk files to arbitrary path with ThemeCenter privilege.
NA - CVE-2024-49412 - Improper input validation in Settings prior to...
Improper input validation in Settings prior to SMR Dec-2024 Release 1 allows local attackers to broadcast signal for discovering Bluetooth on Galaxy Watch.
NA - CVE-2024-49413 - Improper Verification of Cryptographic...
Improper Verification of Cryptographic Signature in SmartSwitch prior to SMR Dec-2024 Release 1 allows local attackers to install malicious applications.
NA - CVE-2024-49414 - Authentication Bypass Using an Alternate Path...
Authentication Bypass Using an Alternate Path in Dex Mode prior to SMR Dec-2024 Release 1 allows physical attackers to temporarily access to recent app list.