NA - CVE-2024-39709 - Incorrect file permissions in Ivanti Connect...
Incorrect file permissions in Ivanti Connect Secure before version 22.6R2 and Ivanti Policy Secure before version 22.6R1 allow a local authenticated attacker to escalate their privileges.
NA - CVE-2024-39710 - Argument injection in Ivanti Connect Secure...
Argument injection in Ivanti Connect Secure before version 22.7R2 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to...
NA - CVE-2024-39711 - Argument injection in Ivanti Connect Secure...
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to...
NA - CVE-2024-39712 - Argument injection in Ivanti Connect Secure...
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to...
Medium - CVE-2024-8874 - The AJAX Login and Registration modal popup +...
The AJAX Login and Registration modal popup + inline form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the...
Medium - CVE-2024-8985 - The Social Proof (Testimonial) Slider plugin...
The Social Proof (Testimonial) Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's spslider-block shortcode in all versions up to, and including, 2.2.4...
NA - CVE-2024-9426 - The Aqua SVG Sprite plugin for WordPress is...
The Aqua SVG Sprite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.0.14 due to insufficient input sanitization and...
NA - CVE-2024-9578 - The Hide Links plugin for WordPress is...
The Hide Links plugin for WordPress is vulnerable to unauthorized shortcode execution due to do_shortcode being hooked through the comment_text filter in all versions up to and including 1.4.2....
Medium - CVE-2024-9614 - The Constant Contact Forms by MailMunch plugin...
The Constant Contact Forms by MailMunch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions...
Medium - CVE-2024-10529 - The Kognetiks Chatbot for WordPress plugin for...
The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_assistant() function in all versions up...