NA - CVE-2025-23374 - Dell Networking Switches running Enterprise...
Dell Networking Switches running Enterprise SONiC OS, version(s) prior to 4.4.1 and 4.2.3, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A high privileged attacker...
NA - CVE-2024-10309 - The Tracking Code Manager WordPress plugin...
The Tracking Code Manager WordPress plugin before 2.4.0 does not sanitise and escape some of its metabox settings when outputing them in the page, which could allow users with a role as low as...
NA - CVE-2024-12400 - The tourmaster WordPress plugin before 5.3.5...
The tourmaster WordPress plugin before 5.3.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.
NA - CVE-2024-12638 - The Bulk Me Now! WordPress plugin through 2.0...
The Bulk Me Now! WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against...
NA - CVE-2024-12708 - The Bulk Me Now! WordPress plugin through 2.0...
The Bulk Me Now! WordPress plugin through 2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could...
NA - CVE-2024-12709 - The Bulk Me Now! WordPress plugin through 2.0...
The Bulk Me Now! WordPress plugin through 2.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.
Medium - CVE-2024-12921 - The EthereumICO plugin for WordPress is...
The EthereumICO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ethereum-ico shortcode in all versions up to, and including, 2.4.6 due to insufficient input...
Medium - CVE-2024-13457 - The Event Tickets and Registration plugin for...
The Event Tickets and Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.18.1 via the tc-order-id parameter due to missing...
Medium - CVE-2024-13642 - The Stratum – Elementor Widgets plugin for...
The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Hotspot widget in all versions up to, and including, 1.4.7 due to...