Medium - CVE-2024-12506 - The NACC WordPress Plugin plugin for WordPress...
The NACC WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'nacc' shortcode in all versions up to, and including, 4.1.0 due to...
Medium - CVE-2024-12509 - The Embed Twine plugin for WordPress is...
The Embed Twine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'embed_twine' shortcode in all versions up to, and including, 0.1.0 due to...
Critical - CVE-2024-12571 - The Store Locator for WordPress with Google...
The Store Locator for WordPress with Google Maps – LotsOfLocales plugin for WordPress is vulnerable to Local File Inclusion in version 3.98.9 via the 'sl_engine' parameter. This makes it...
Medium - CVE-2024-9503 - The Maintenance & Coming Soon Redirect...
The Maintenance & Coming Soon Redirect Animation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the...
Medium - CVE-2024-9619 - The WP SHAPES plugin for WordPress is...
The WP SHAPES plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output...
NA - CVE-2024-7726 - There exists an unauthenticated accessible JTAG...
There exists an unauthenticated accessible JTAG port on the Kioxia PM6, PM7 and CM6 devices - On the Kioxia CM6, PM6 and PM7 disk drives it was discovered that the 2 main CPU cores of the SoC can...
NA - CVE-2024-12014 - Path Traversal and Insecure Direct Object...
Path Traversal and Insecure Direct Object Reference (IDOR) vulnerabilities in the eSignaViewer component in eSigna product versions 1.0 to 1.5 on all platforms allow an unauthenticated attacker to...
Medium - CVE-2024-28767 - IBM Security Directory Integrator 7.2.0 through...
IBM Security Directory Integrator 7.2.0 through 7.2.0.13 and 10.0.0 through 10.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially...
High - CVE-2024-40695 - IBM Cognos Analytics 11.2.0 through 11.2.4 FP4...
IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface....
Critical - CVE-2024-51466 - IBM Cognos Analytics 11.2.0 through 11.2.4 FP4...
IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 is vulnerable to an Expression Language (EL) Injection vulnerability. A remote attacker could exploit this vulnerability...