Medium - CVE-2024-11435 - The salavat counter Plugin plugin for WordPress...
The salavat counter Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 0.9.1 due to insufficient...
Medium - CVE-2024-11438 - The StreamWeasels Online Status Bar plugin for...
The StreamWeasels Online Status Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sw-status-bar' shortcode in all versions up to, and including,...
Medium - CVE-2024-11440 - The Grey Owl Lightbox plugin for WordPress is...
The Grey Owl Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gol_button' shortcode in all versions up to, and including, 1.6.1 due to...
Medium - CVE-2024-11447 - The Community by PeepSo – Download from...
The Community by PeepSo – Download from PeepSo.com plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘filter’ parameter in all versions up to, and including, 6.4.6.2 due...
Medium - CVE-2024-11455 - The Include Mastodon Feed plugin for WordPress...
The Include Mastodon Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'include-mastodon-feed' shortcode in all versions up to, and including,...
Medium - CVE-2024-11456 - The Run Contests, Raffles, and Giveaways with...
The Run Contests, Raffles, and Giveaways with ContestsWP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL...
NA - CVE-2024-11595 - FiveCo RAP dissector infinite loop in Wireshark...
FiveCo RAP dissector infinite loop in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file
NA - CVE-2024-30896 - InfluxDB through 2.7.10 allows allAccess...
InfluxDB through 2.7.10 allows allAccess administrators to retrieve all raw tokens via an "influx auth ls" command. NOTE: the supplier indicates that this is intentional but is a "poor design...
Medium - CVE-2024-45663 - IBM Db2 for Linux, UNIX and Windows (includes...
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.