Medium - CVE-2024-41176 - The MPD package included in TwinCAT/BSD allows...
The MPD package included in TwinCAT/BSD allows an authenticated, low-privileged local attacker to induce a Denial-of-Service (DoS) condition on the daemon and execute code in the context of user...
NA - CVE-2024-8046 - The Logo Showcase Ultimate – Logo Carousel,...
The Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including,...
Medium - CVE-2024-7791 - The 140+ Widgets | Xpro Addons For Elementor –...
The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘arrow’ parameter within the Post Grid widget in all versions up to,...
Medium - CVE-2024-8197 - The Visual Sound plugin for WordPress is...
The Visual Sound plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.03. This is due to missing or incorrect nonce validation on a function....
NA - CVE-2024-8207 - In certain highly specific configurations of...
In certain highly specific configurations of the host system and MongoDB server binary installation on Linux Operating Systems, it may be possible for a unintended actor with host-level access to...
NA - CVE-2024-3980 - The product allows user input to control or...
The product allows user input to control or influence paths or file names that are used in filesystem operations, allowing the attacker to access or modify system files or other files that are...