NA - CVE-2024-6910 - The EventON WordPress plugin before 2.2.17 does...
The EventON WordPress plugin before 2.2.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when...
NA - CVE-2024-7687 - The AZIndex WordPress plugin through 0.8.1 does...
The AZIndex WordPress plugin through 0.8.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored...
NA - CVE-2024-7688 - The AZIndex WordPress plugin through 0.8.1 does...
The AZIndex WordPress plugin through 0.8.1 does not have CSRF checks in some places, which could allow attackers to make logged in admin delete arbitrary indexes via a CSRF attack
NA - CVE-2024-7689 - The Snapshot Backup WordPress plugin through...
The Snapshot Backup WordPress plugin through 2.1.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add...
NA - CVE-2024-7918 - The Pocket Widget WordPress plugin through...
The Pocket Widget WordPress plugin through 0.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting...
NA - CVE-2024-45203 - Improper authorization in handler for custom...
Improper authorization in handler for custom URL scheme issue in "@cosme" App for Android versions prior 5.69.0 and "@cosme" App for iOS versions prior to 6.74.0 allows an attacker to lead a user...
NA - CVE-2024-37288 - A deserialization issue in Kibana can lead to...
A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. This issue only affects users that use Elastic...
NA - CVE-2024-6572 - Improper host key checking in active check...
Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem' in Checkmk before Checkmk 2.3.0p15, 2.2.0p33, 2.1.0p48 and 2.0.0...
NA - CVE-2024-8601 - This vulnerability exists in TechExcel Back...
This vulnerability exists in TechExcel Back Office Software versions prior to 1.0.0 due to improper access controls on certain API endpoints. An authenticated remote attacker could exploit this...