Medium - CVE-2024-10670 - The Primary Addon for Elementor plugin for...
The Primary Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.6.2 via the [prim_elementor_template] shortcode due to...
Medium - CVE-2024-10780 - The Restaurant & Cafe Addon for Elementor...
The Restaurant & Cafe Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.5.9 via the 'narestaurant_elementor_template'...
Medium - CVE-2024-10798 - The Royal Elementor Addons and Templates plugin...
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.7.1003 via the 'wpr-template' shortcode due to...
Critical - CVE-2024-11082 - The Tumult Hype Animations plugin for WordPress...
The Tumult Hype Animations plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the hypeanimations_panel() function in all versions up to, and...
Critical - CVE-2024-11103 - The Contest Gallery plugin for WordPress is...
The Contest Gallery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 24.0.7. This is due to the plugin not properly validating a...
NA - CVE-2024-22037 - The uyuni-server-attestation systemd service...
The uyuni-server-attestation systemd service needs a database_password environment variable. This file has 640 permission, and cannot be shown users, but the environment is still exposed by systemd...
NA - CVE-2024-49502 - A Improper Neutralization of Input During Web...
A Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in the Setup Wizard, HTTP Proxy credentials pane in spacewalk-web allows...
NA - CVE-2024-49503 - A Improper Neutralization of Input During Web...
A Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SUSE manager allows attackers to execute Javascript code in the organization...