NA - CVE-2024-1108 - The Plugin Groups plugin for WordPress is...
The Plugin Groups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the admin_init() function in all versions up to, and including, 2.0.6....
NA - CVE-2024-1631 - Impact: The library offers a function to...
Impact: The library offers a function to generate an ed25519 key pair via Ed25519KeyIdentity.generate with an optional param to provide a 32 byte seed value, which will then be used as the secret...
NA - CVE-2024-25603 - Stored cross-site scripting (XSS) vulnerability...
Stored cross-site scripting (XSS) vulnerability in the Dynamic Data Mapping module's DDMForm in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13,...
NA - CVE-2024-26266 - Multiple stored cross-site scripting (XSS)...
Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.2.0 through 7.4.3.13, and older unsupported versions, and Liferay DXP 7.4 before update 10, 7.3 before update 4, 7.2...
NA - CVE-2024-26269 - Cross-site scripting (XSS) vulnerability in the...
Cross-site scripting (XSS) vulnerability in the Frontend JS module's portlet.js in Liferay Portal 7.2.0 through 7.4.3.37, and Liferay DXP 7.4 before update 38, 7.3 before update 11, 7.2 before...
NA - CVE-2024-1501 - The Database Reset plugin for WordPress is...
The Database Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.22. This is due to missing or incorrect nonce validation on the...
NA - CVE-2024-1562 - The WooCommerce Google Sheet Connector plugin...
The WooCommerce Google Sheet Connector plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the execute_post_data function in all versions up...
NA - CVE-2024-1669 - Out of bounds memory access in Blink in Google...
Out of bounds memory access in Blink in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity:...
NA - CVE-2024-1670 - Use after free in Mojo in Google Chrome prior...
Use after free in Mojo in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
NA - CVE-2024-1671 - Inappropriate implementation in Site Isolation...
Inappropriate implementation in Site Isolation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security...