NA - CVE-2024-53143 - In the Linux kernel, the following...
In the Linux kernel, the following vulnerability has been resolved: fsnotify: Fix ordering of iput() and watched_objects decrement Ensure the superblock is kept alive until we're done with...
High - CVE-2024-11010 - The FileOrganizer – Manage WordPress and...
The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.4 via the 'default_lang'...
Medium - CVE-2024-11367 - The Smoove connector for Elementor forms plugin...
The Smoove connector for Elementor forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions...
Medium - CVE-2024-11374 - The TWChat – Send or receive messages from...
The TWChat – Send or receive messages from users plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in...
Medium - CVE-2024-12128 - The Simple Ecommerce Shopping Cart Plugin- Sell...
The Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘monthly_sales_current_year’ parameter in all...
Medium - CVE-2024-12253 - The Simple Ecommerce Shopping Cart Plugin- Sell...
The Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'save_settings',...
High - CVE-2024-12270 - The Beautiful taxonomy filters plugin for...
The Beautiful taxonomy filters plugin for WordPress is vulnerable to SQL Injection via the 'selects[0][term]' parameter in all versions up to, and including, 2.4.3 due to insufficient...
Medium - CVE-2024-11380 - The Mini Program API plugin for WordPress is...
The Mini Program API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'qvideo' shortcode in all versions up to, and including, 1.4.5 due to...
Medium - CVE-2024-11457 - The Feedpress Generator – External RSS Frontend...
The Feedpress Generator – External RSS Frontend Customizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and...
Medium - CVE-2024-11464 - The Easy Code Snippets plugin for WordPress is...
The Easy Code Snippets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.0.2 due to insufficient input...