Medium - CVE-2024-8724 - The Waitlist Woocommerce ( Back in stock...
The Waitlist Woocommerce ( Back in stock notifier ) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in...
Medium - CVE-2024-8797 - The WP Booking System – Booking Calendar plugin...
The WP Booking System – Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the...
Medium - CVE-2023-3410 - The Bricks theme for WordPress is vulnerable to...
The Bricks theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘customTag' attribute in versions up to, and including, 1.10.1 due to insufficient input sanitization and...
High - CVE-2024-6482 - The Login with phone number plugin for...
The Login with phone number plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.49. This is due to a lack of validation and missing capability check...
NA - CVE-2024-8862 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, has been found in h2oai h2o-3 3.46.0.4. This issue affects the function getConnectionSafe of the file /dtale/chart-data/1 of the component JDBC...
NA - CVE-2024-8863 - A vulnerability, which was classified as...
A vulnerability, which was classified as problematic, was found in aimhubio aim up to 3.24. Affected is the function dangerouslySetInnerHTML of the file textbox.tsx of the component Text Explorer....
NA - CVE-2024-8762 - A vulnerability was found in code-projects Crud...
A vulnerability was found in code-projects Crud Operation System 1.0. It has been classified as critical. This affects an unknown part of the file /updatedata.php. The manipulation of the argument...
Medium - CVE-2024-43180 - IBM Concert 1.0 does not set the secure...
IBM Concert 1.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this...
Medium - CVE-2024-8656 - The WPFactory Helper plugin for WordPress is...
The WPFactory Helper plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and...
NA - CVE-2024-38816 - Applications serving static resources through...
Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and...