Medium - CVE-2024-8477 - The Newsletter, SMTP, Email marketing and...
The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
High - CVE-2024-9022 - The TS Poll – Survey, Versus Poll, Image Poll,...
The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 2.3.9 due to...
Medium - CVE-2024-9067 - The Youzify – BuddyPress Community, User...
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing...
Medium - CVE-2024-9074 - The Advanced Blocks Pro plugin for WordPress is...
The Advanced Blocks Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and...
Medium - CVE-2024-9520 - The UserPlus plugin for WordPress is vulnerable...
The UserPlus plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all versions up to, and including,...
NA - CVE-2024-9156 - The TI WooCommerce Wishlist WordPress plugin...
The TI WooCommerce Wishlist WordPress plugin through 2.8.2 is vulnerable to SQL Injection due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the...
NA - CVE-2024-9781 - AppleTalk and RELOAD Framing dissector crash in...
AppleTalk and RELOAD Framing dissector crash in Wireshark 4.4.0 and 4.2.0 to 4.2.7 allows denial of service via packet injection or crafted capture file
NA - CVE-2024-6747 - Information leakage in mknotifyd in Checkmk...
Information leakage in mknotifyd in Checkmk before 2.3.0p18, 2.2.0p36, 2.1.0p49 and in 2.0.0p39 (EOL) allows attacker to get potentially sensitive data
NA - CVE-2024-7049 - In version v0.3.8 of open-webui/open-webui, a...
In version v0.3.8 of open-webui/open-webui, a vulnerability exists where a token is returned when a user with a pending role logs in. This allows the user to perform actions without admin...