Critical - CVE-2024-10542 - The Spam protection, Anti-Spam, FireWall by...
The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS spoofing on the...
High - CVE-2024-10570 - The Security & Malware scan by CleanTalk plugin...
The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to unauthorized SQL Injection due to an authorization bypass via reverse DNS spoofing on the checkWithoutToken function...
High - CVE-2024-10781 - The Spam protection, Anti-Spam, FireWall by...
The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an missing empty value check on the 'api_key'...
Medium - CVE-2024-10857 - The Product Input Fields for WooCommerce plugin...
The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9 via the handle_downloads() function due to insufficient...
Medium - CVE-2024-11002 - The The InPost Gallery plugin for WordPress is...
The The InPost Gallery plugin for WordPress is vulnerable to arbitrary shortcode execution via the inpost_gallery_get_shortcode_template AJAX action in all versions up to, and including, 2.1.4.2....
NA - CVE-2024-6476 - Gee-netics, member of the AXIS Camera Station...
Gee-netics, member of the AXIS Camera Station Pro Bug Bounty Program has found that it is possible for a non-admin user to gain system privileges by redirecting a file deletion upon service...
NA - CVE-2024-6749 - Seth Fogie, member of the AXIS Camera Station...
Seth Fogie, member of the AXIS Camera Station Pro Bug Bounty Program, has found that the Incident report feature may expose sensitive credentials on the AXIS Camera Station windows client. If...
Medium - CVE-2024-11202 - Multiple plugins for WordPress are vulnerable...
Multiple plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the cminds_free_guide shortcode in various versions due to insufficient input sanitization and output escaping....
NA - CVE-2024-28038 - The web interface of the affected devices...
The web interface of the affected devices processes a cookie value improperly, leading to a stack buffer overflow. More precisely, giving too long character string to MFPSESSIONID parameter results...
NA - CVE-2024-28955 - Affected devices create coredump files when...
Affected devices create coredump files when crashed, storing them with world-readable permission. Any local user of the device can examine the coredump files, and research the memory contents. As...