Critical - CVE-2024-11103 - The Contest Gallery plugin for WordPress is...
The Contest Gallery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 24.0.7. This is due to the plugin not properly validating a...
NA - CVE-2024-22037 - The uyuni-server-attestation systemd service...
The uyuni-server-attestation systemd service needs a database_password environment variable. This file has 640 permission, and cannot be shown users, but the environment is still exposed by systemd...
NA - CVE-2024-49502 - A Improper Neutralization of Input During Web...
A Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in the Setup Wizard, HTTP Proxy credentials pane in spacewalk-web allows...
NA - CVE-2024-49503 - A Improper Neutralization of Input During Web...
A Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SUSE manager allows attackers to execute Javascript code in the organization...
Critical - CVE-2024-8672 - The Widget Options – The #1 WordPress Widget &...
The Widget Options – The #1 WordPress Widget & Block Control Plugin plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.7 via the display logic...
NA - CVE-2024-11620 - Improper Control of Generation of Code...
Improper Control of Generation of Code ('Code Injection') vulnerability in Rank Math SEO allows Code Injection.This issue affects Rank Math SEO: from n/a through 1.0.231.