NA - CVE-2022-33860 - Rejected reason: ** REJECT ** DO NOT USE THIS...
Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-43775. Reason: This record is a duplicate of CVE-2023-43775. Notes: All CVE users should reference CVE-2023-43775...
NA - CVE-2024-53278 - Cross-site scripting vulnerability exists in WP...
Cross-site scripting vulnerability exists in WP Admin UI Customize versions prior to ver 1.5.14. If a malicious admin user customizes the admin screen with some malicious contents, an arbitrary...
NA - CVE-2024-10471 - The Everest Forms WordPress plugin before...
The Everest Forms WordPress plugin before 3.0.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting...
Critical - CVE-2024-10542 - The Spam protection, Anti-Spam, FireWall by...
The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS spoofing on the...
High - CVE-2024-10570 - The Security & Malware scan by CleanTalk plugin...
The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to unauthorized SQL Injection due to an authorization bypass via reverse DNS spoofing on the checkWithoutToken function...
High - CVE-2024-10781 - The Spam protection, Anti-Spam, FireWall by...
The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an missing empty value check on the 'api_key'...
Medium - CVE-2024-10857 - The Product Input Fields for WooCommerce plugin...
The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9 via the handle_downloads() function due to insufficient...
Medium - CVE-2024-11002 - The The InPost Gallery plugin for WordPress is...
The The InPost Gallery plugin for WordPress is vulnerable to arbitrary shortcode execution via the inpost_gallery_get_shortcode_template AJAX action in all versions up to, and including, 2.1.4.2....
NA - CVE-2024-6476 - Gee-netics, member of the AXIS Camera Station...
Gee-netics, member of the AXIS Camera Station Pro Bug Bounty Program has found that it is possible for a non-admin user to gain system privileges by redirecting a file deletion upon service...
NA - CVE-2024-6749 - Seth Fogie, member of the AXIS Camera Station...
Seth Fogie, member of the AXIS Camera Station Pro Bug Bounty Program, has found that the Incident report feature may expose sensitive credentials on the AXIS Camera Station windows client. If...