NA - CVE-2024-38654 - Improper bounds checking in Ivanti Secure...
Improper bounds checking in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker with admin privileges to cause a denial of service.
NA - CVE-2024-38655 - Argument injection in Ivanti Connect Secure...
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote...
NA - CVE-2024-38656 - Argument injection in Ivanti Connect Secure...
Argument injection in Ivanti Connect Secure before version 22.7R2.2 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to...
NA - CVE-2024-39709 - Incorrect file permissions in Ivanti Connect...
Incorrect file permissions in Ivanti Connect Secure before version 22.6R2 and Ivanti Policy Secure before version 22.6R1 allow a local authenticated attacker to escalate their privileges.
NA - CVE-2024-39710 - Argument injection in Ivanti Connect Secure...
Argument injection in Ivanti Connect Secure before version 22.7R2 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to...
NA - CVE-2024-39711 - Argument injection in Ivanti Connect Secure...
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to...
NA - CVE-2024-39712 - Argument injection in Ivanti Connect Secure...
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to...
Medium - CVE-2024-8874 - The AJAX Login and Registration modal popup +...
The AJAX Login and Registration modal popup + inline form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the...
Medium - CVE-2024-8985 - The Social Proof (Testimonial) Slider plugin...
The Social Proof (Testimonial) Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's spslider-block shortcode in all versions up to, and including, 2.2.4...
NA - CVE-2024-9426 - The Aqua SVG Sprite plugin for WordPress is...
The Aqua SVG Sprite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.0.14 due to insufficient input sanitization and...