Medium - CVE-2024-10850 - The Razorpay Payment Button Elementor Plugin...
The Razorpay Payment Button Elementor Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on...
Medium - CVE-2024-10851 - The Razorpay Payment Button Plugin plugin for...
The Razorpay Payment Button Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in...
Medium - CVE-2024-10852 - The Buy one click WooCommerce plugin for...
The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the buy_one_click_export_options AJAX action in all versions up...
Medium - CVE-2024-10853 - The Buy one click WooCommerce plugin for...
The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the removeorder AJAX action in all versions up to, and...
Medium - CVE-2024-10854 - The Buy one click WooCommerce plugin for...
The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the buy_one_click_import_options AJAX action in all...
Medium - CVE-2024-10887 - The NiceJob plugin for WordPress is vulnerable...
The NiceJob plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes (nicejob-lead, nicejob-review, nicejob-engage, nicejob-badge,...
NA - CVE-2024-32839 - SQL injection in Ivanti Endpoint Manager before...
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote...
NA - CVE-2024-32841 - SQL injection in Ivanti Endpoint Manager before...
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote...
NA - CVE-2024-32844 - SQL injection in Ivanti Endpoint Manager before...
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote...