Medium - CVE-2024-9682 - The Royal Elementor Addons and Templates plugin...
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Form Builder widget in all versions up to, and including, 1.7.1001...
Critical - CVE-2024-11028 - The MultiManager WP – Manage All Your WordPress...
The MultiManager WP – Manage All Your WordPress Sites Easily plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.5. This is due to the user...
NA - CVE-2024-8001 - A vulnerability was found in VIWIS LMS 9.11. It...
A vulnerability was found in VIWIS LMS 9.11. It has been classified as critical. Affected is an unknown function of the component Print Handler. The manipulation leads to missing authorization. It...
NA - CVE-2024-4741 - Issue summary: Calling the OpenSSL API function...
Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause memory to be accessed that was previously freed in some situations Impact summary: A use after free can have a range of...
NA - CVE-2024-47574 - A authentication bypass using an alternate path...
A authentication bypass using an alternate path or channel in Fortinet FortiClientWindows version 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0, and 6.4.10 through 6.4.0 allows...
NA - CVE-2022-45157 - A vulnerability has been identified in the way...
A vulnerability has been identified in the way that Rancher stores vSphere's CPI (Cloud Provider Interface) and CSI (Container Storage Interface) credentials used to deploy clusters through...
NA - CVE-2024-11159 - Using remote content in OpenPGP encrypted...
Using remote content in OpenPGP encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird < 128.4.3 and Thunderbird < 132.0.1.
NA - CVE-2024-48989 - A vulnerability in the PROFINET stack...
A vulnerability in the PROFINET stack implementation of the IndraDrive (all versions) of Bosch Rexroth allows an attacker to cause a denial of service, rendering the device unresponsive by sending...
NA - CVE-2024-11165 - An information disclosure vulnerability exists...
An information disclosure vulnerability exists in the backup configuration process where the SAS token is not masked in the configuration response. This oversight results in sensitive information...
NA - CVE-2024-48510 - Directory Traversal vulnerability in DotNetZip...
Directory Traversal vulnerability in DotNetZip v.1.16.0 and before allows a remote attacker to execute arbitrary code via the src/Zip.Shared/ZipEntry.Extract.cs component NOTE: This vulnerability...