Medium - CVE-2024-8629 - The WooCommerce Multilingual & Multicurrency...
The WooCommerce Multilingual & Multicurrency with WPML plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL...
NA - CVE-2024-8488 - The Survey Maker plugin for WordPress is...
The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Survey fields in all versions up to, and including, 4.9.7 due to insufficient input sanitization and output...
NA - CVE-2024-8884 - CWE-200: Exposure of Sensitive Information to...
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause exposure of credentials when attacker has access to application on network over http
NA - CVE-2024-9005 - CWE-502: Deserialization of Untrusted Data...
CWE-502: Deserialization of Untrusted Data vulnerability exists that could allow code to be remotely executed on the server when unsafely deserialized data is posted to the web server.
Medium - CVE-2024-9207 - The BuddyPress Docs plugin for WordPress is...
The BuddyPress Docs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and...
Medium - CVE-2024-8431 - The Photo Gallery, Images, Slider in Rbs Image...
The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajaxGetGalleryJson() function in...
Medium - CVE-2024-8482 - The Royal Elementor Addons and Templates plugin...
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 1.3.982 due to insufficient...
NA - CVE-2024-33506 - An exposure of sensitive information to an...
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManager 7.4.2 and below, 7.2.5 and below, 7.0.12 and below allows a remote authenticated attacker...
NA - CVE-2024-45330 - A use of externally-controlled format string in...
A use of externally-controlled format string in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.2 through 7.2.5 allows attacker to escalate its privileges via specially crafted requests.
NA - CVE-2024-45880 - A command injection vulnerability exists in...
A command injection vulnerability exists in Motorola CX2L router v1.0.2 and below. The vulnerability is present in the SetStationSettings function. The system directly invokes the system function...