Medium - CVE-2024-11008 - The Members – Membership & User Role Editor...
The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.10 via the WordPress core search...
High - CVE-2024-11840 - The RapidLoad – Optimize Web Vitals...
The RapidLoad – Optimize Web Vitals Automatically plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the uucss_data,...
Medium - CVE-2024-12294 - The Last Viewed Posts by WPBeginner plugin for...
The Last Viewed Posts by WPBeginner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.1 via the 'get_legacy_cookies' function....
Medium - CVE-2024-12325 - The Waymark plugin for WordPress is vulnerable...
The Waymark plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, 1.4.1 due to insufficient input sanitization and...
Low - CVE-2023-23472 - IBM InfoSphere DataStage Flow Designer...
IBM InfoSphere DataStage Flow Designer (InfoSphere Information Server 11.7) could allow an authenticated user to obtain sensitive information that could aid in further attacks against the system.
Medium - CVE-2024-11351 - The Restrict – membership, site, content and...
The Restrict – membership, site, content and user access restrictions for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.8...
Medium - CVE-2024-51460 - IBM InfoSphere Information Server 11.7 could...
IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information when a detailed technical error message is returned in a stack trace. This information could...
NA - VU#164934 - PDQ Deploy allows reuse of deleted credentials that can compromise a device and facilitate lateral movement
OverviewPDQ Deploy is a service intended for usage by system administrators for the deployment of software or updates to targeted machines within their network. PDQ Deploy uses "run modes" to...
NA - CVE-2024-50585 - Users who click on a malicious link or visit a...
Users who click on a malicious link or visit a website under the control of an attacker can be infected with arbitrary JavaScript which is running in the context of the "Numerix License Server...
NA - CVE-2024-28139 - The www-data user can elevate its privileges...
The www-data user can elevate its privileges because sudo is configured to allow the execution of the mount command as root without a password. Therefore, the privileges can be escalated to the...