Medium - CVE-2024-49340 - IBM Watson Studio Local 1.2.3 is vulnerable to...
IBM Watson Studio Local 1.2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
Medium - CVE-2024-8541 - The Discount Rules for WooCommerce – Create...
The Discount Rules for WooCommerce – Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of...
Medium - CVE-2024-8787 - The Smart Online Order for Clover plugin for...
The Smart Online Order for Clover plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in...
Medium - CVE-2024-9104 - The UltimateAI plugin for WordPress is...
The UltimateAI plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.8.3. This is due to the improper empty value check and a missing default activated...
Critical - CVE-2024-9105 - The UltimateAI plugin for WordPress is...
The UltimateAI plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.8.3. This is due to insufficient verification on the user being supplied in the...
High - CVE-2024-9305 - The AppPresser – Mobile App Framework plugin...
The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.4.4. This is due to the...
Medium - CVE-2024-9521 - The SEO Manager plugin for WordPress is...
The SEO Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post meta in versions up to, and including, 1.9 due to insufficient input sanitization and output escaping on...
Critical - CVE-2024-9634 - The GiveWP – Donation Plugin and Fundraising...
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.16.3 via deserialization of untrusted input...
Medium - CVE-2024-9647 - The Kama SpamBlock plugin for WordPress is...
The Kama SpamBlock plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST values in all versions up to, and including, 1.8.2 due to insufficient input sanitization and...