NA - CVE-2024-6594 - Improper Handling of Exceptional Conditions...
Improper Handling of Exceptional Conditions vulnerability in the WatchGuard Single Sign-On Client on Windows causes the client to crash while handling malformed commands. An attacker with network...
NA - CVE-2024-4657 - Improper Neutralization of Input During Web...
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Talent Software BAP Automation allows Stored XSS.This issue affects BAP...
Medium - CVE-2024-8546 - The ElementsKit Elementor addons plugin for...
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video widget in all versions up to, and including, 3.2.7 due to insufficient...
Critical - CVE-2024-8275 - The The Events Calendar plugin for WordPress is...
The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_next_event' function in all versions up to, and...
Medium - CVE-2024-8668 - The ShopLentor – WooCommerce Builder for...
The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
NA - CVE-2024-6845 - The Chatbot with ChatGPT WordPress plugin...
The Chatbot with ChatGPT WordPress plugin before 2.4.6 does not have proper authorization in one of its REST endpoint, allowing unauthenticated users to retrieve the encoded key and then decode it,...
NA - CVE-2024-7878 - The WP ULike WordPress plugin before 4.7.4...
The WP ULike WordPress plugin before 4.7.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks...
NA - CVE-2024-7892 - The adstxt Plugin WordPress plugin through...
The adstxt Plugin WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
Medium - CVE-2024-8658 - The myCred – Loyalty Points and Rewards plugin...
The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification plugin for...
NA - CVE-2024-3866 - The Ninja Forms Contact Form plugin for...
The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Self-Based Cross-Site Scripting via the 'Referer' header in all versions up to, and including, 3.8.15 due to...