Medium - CVE-2024-9610 - The Language Switcher plugin for WordPress is...
The Language Switcher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and...
Medium - CVE-2024-9611 - The Increase upload file size & Maximum...
The Increase upload file size & Maximum Execution Time limit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the...
Medium - CVE-2024-9616 - The BlockMeister – Block Pattern Builder plugin...
The BlockMeister – Block Pattern Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions...
Critical - CVE-2024-9707 - The Hunk Companion plugin for WordPress is...
The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the /wp-json/hc/v1/themehunk-import REST API endpoint in...
NA - CVE-2024-9855 - A vulnerability was found in 07FLYCMS,...
A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been declared as critical. Affected by this vulnerability is the function uploadFile of the file...
NA - CVE-2024-9856 - A vulnerability was found in 07FLYCMS,...
A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been rated as problematic. Affected by this issue is some unknown functionality of the component System Settings Page....
NA - CVE-2024-6657 - A denial of service may be caused to a single...
A denial of service may be caused to a single peripheral device in a BLE network when multiple central devices continuously connect and disconnect to the peripheral. A hard reset is required to...
NA - CVE-2024-8530 - CWE-306: Missing Authentication for Critical...
CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause exposure of private data when an already generated “logcaptures” archive is accessed directly by HTTPS.
NA - CVE-2024-8531 - CWE-347: Improper Verification of Cryptographic...
CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that could compromise the Data Center Expert software when an upgrade bundle is manipulated to include arbitrary bash...
NA - CVE-2024-9002 - CWE-269: Improper Privilege Management...
CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity, and availability of the workstation when non-admin...