Medium - CVE-2024-28770 - IBM Security Directory Integrator 7.2.0 and IBM...
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to...
Medium - CVE-2024-28771 - IBM Security Directory Integrator 7.2.0 and IBM...
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to...
NA - CVE-2024-12280 - The WP Customer Area WordPress plugin through...
The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF check in place when deleting its logs, which could allow attackers to make a logged in to delete them via a CSRF attack
NA - CVE-2024-12321 - The WC Affiliate WordPress plugin through...
The WC Affiliate WordPress plugin through 2.3.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used...
NA - CVE-2024-12436 - The WP Customer Area WordPress plugin through...
The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
NA - CVE-2024-12773 - The Altra Side Menu WordPress plugin through...
The Altra Side Menu WordPress plugin through 2.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
NA - CVE-2024-12774 - The Altra Side Menu WordPress plugin through...
The Altra Side Menu WordPress plugin through 2.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins delete arbitrary menu via a CSRF attack
NA - CVE-2024-13052 - The Dental Optimizer Patient Generator App...
The Dental Optimizer Patient Generator App WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting...
NA - CVE-2024-13055 - The Dyn Business Panel WordPress plugin through...
The Dyn Business Panel WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used...
NA - CVE-2024-13056 - The Dyn Business Panel WordPress plugin through...
The Dyn Business Panel WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used...