NA - CVE-2024-7652 - An error in the ECMA-262 specification relating...
An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption and an exploitable crash. This vulnerability...
NA - CVE-2024-34156 - Calling Decoder.Decode on a message which...
Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635.
NA - CVE-2024-44844 - DrayTek Vigor3900 v1.5.1.6 was discovered to...
DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the name parameter in the run_command function.
NA - CVE-2024-44845 - DrayTek Vigor3900 v1.5.1.6 was discovered to...
DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the value parameter in the filter_string function.
NA - CVE-2024-44837 - A cross-site scripting (XSS) vulnerability in...
A cross-site scripting (XSS) vulnerability in the component \bean\Manager.java of Drug v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the user...
NA - CVE-2024-6445 - Improper Limitation of a Pathname to a...
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DataFlowX Technology DataDiodeX allows Path Traversal.This issue affects DataDiodeX: before...
Critical - CVE-2024-7493 - The WPCOM Member plugin for WordPress is...
The WPCOM Member plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.5.2.1. This is due to the plugin allowing arbitrary data to be passed to...
Medium - CVE-2024-7599 - The Advanced Sermons plugin for WordPress is...
The Advanced Sermons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘sermon_video_embed’ parameter in all versions up to, and including, 3.3 due to insufficient input...