NA - CVE-2024-54663 - An issue was discovered in the Webmail Classic...
An issue was discovered in the Webmail Classic UI in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Local File Inclusion (LFI) vulnerability exists in the /h/rest endpoint, allowing...
NA - CVE-2024-56327 - pyrage is a set of Python bindings for the rage...
pyrage is a set of Python bindings for the rage file encryption library (age in Rust). `pyrage` uses the Rust `age` crate for its underlying operations, and `age` is vulnerable to...
Medium - CVE-2024-11439 - The ScanCircle plugin for WordPress is...
The ScanCircle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'scancircle' shortcode in all versions up to, and including, 2.9.2 due to...
Medium - CVE-2024-11748 - The Taeggie Feed plugin for WordPress is...
The Taeggie Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'taeggie-feed' shortcode in all versions up to, and including, 0.1.9 due to...
Medium - CVE-2024-11881 - The Easy Waveform Player plugin for WordPress...
The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'easywaveformplayer' shortcode in all versions up to, and including, 1.2.0...
Medium - CVE-2024-12500 - The Philantro – Donations and Donor Management...
The Philantro – Donations and Donor Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes like 'donate' in all versions up to, and...
Medium - CVE-2024-12513 - The Contests by Rewards Fuel plugin for...
The Contests by Rewards Fuel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'RF_CONTEST' shortcode in all versions up to, and including, 2.0.65...
NA - CVE-2024-47480 - Dell Inventory Collector Client, versions prior...
Dell Inventory Collector Client, versions prior to 12.7.0, contains an Improper Link Resolution Before File Access vulnerability. A low-privilege attacker with local access may exploit this...
Medium - CVE-2024-11254 - The AMP for WP – Accelerated Mobile Pages...
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the disqus_name parameter in all versions up to, and including, 1.1.1 due to...