Medium - CVE-2024-11418 - The Additional Order Filters for WooCommerce...
The Additional Order Filters for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shipping_method_filter' parameter in all versions up to, and...
High - CVE-2024-49353 - IBM Watson Speech Services Cartridge for IBM...
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data 4.0.0 through 5.0.2 does not properly check inputs to resources that are used concurrently, which might lead to unexpected states,...
NA - CVE-2018-11881 - Rejected reason: This CVE ID has been rejected...
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. This CVE ID is unused and any reference to it should be ignored.
NA - CVE-2022-33860 - Rejected reason: ** REJECT ** DO NOT USE THIS...
Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-43775. Reason: This record is a duplicate of CVE-2023-43775. Notes: All CVE users should reference CVE-2023-43775...
NA - CVE-2024-53278 - Cross-site scripting vulnerability exists in WP...
Cross-site scripting vulnerability exists in WP Admin UI Customize versions prior to ver 1.5.14. If a malicious admin user customizes the admin screen with some malicious contents, an arbitrary...
NA - CVE-2024-10471 - The Everest Forms WordPress plugin before...
The Everest Forms WordPress plugin before 3.0.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting...
Critical - CVE-2024-10542 - The Spam protection, Anti-Spam, FireWall by...
The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS spoofing on the...
High - CVE-2024-10570 - The Security & Malware scan by CleanTalk plugin...
The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to unauthorized SQL Injection due to an authorization bypass via reverse DNS spoofing on the checkWithoutToken function...
High - CVE-2024-10781 - The Spam protection, Anti-Spam, FireWall by...
The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an missing empty value check on the 'api_key'...