High - CVE-2024-45063 - The function ctl_write_buffer incorrectly set a...
The function ctl_write_buffer incorrectly set a flag which resulted in a kernel Use-After-Free when a command finished processing. Malicious software running in a guest VM that exposes virtio_scsi...
High - CVE-2024-8178 - The ctl_write_buffer and ctl_read_buffer...
The ctl_write_buffer and ctl_read_buffer functions allocated memory to be returned to userspace, without initializing it. Malicious software running in a guest VM that exposes virtio_scsi can...
NA - CVE-2024-6846 - The Chatbot with ChatGPT WordPress plugin...
The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not validate access on some REST routes, allowing for an unauthenticated user to purge error and chat logs
Medium - CVE-2024-6835 - The Ivory Search – WordPress Search Plugin...
The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 5.5.6 via the ajax_load_posts function. This makes it...
Medium - CVE-2024-45107 - Acrobat Reader versions 20.005.30636,...
Acrobat Reader versions 20.005.30636, 24.002.20964, 24.001.30123, 24.002.20991 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An...
Medium - CVE-2024-5309 - The Form Vibes – Database Manager for Forms...
The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the fv_export_csv,...
Medium - CVE-2024-8363 - The Share This Image plugin for WordPress is...
The Share This Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's STI Buttons shortcode in all versions up to, and including, 2.02 due to insufficient...
Medium - CVE-2024-6332 - The Booking for Appointments and Events...
The Booking for Appointments and Events Calendar – Amelia Premium and Lite plugins for WordPress are vulnerable to unauthorized access of data due to a missing capability check on the...
Medium - CVE-2024-6894 - The RD Station plugin for WordPress is...
The RD Station plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.3.2 due to insufficient input sanitization and output escaping of post...
Medium - CVE-2024-6929 - The Dynamic Featured Image plugin for WordPress...
The Dynamic Featured Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘dfiFeatured’ parameter in all versions up to, and including, 3.7.0 due to insufficient input...