NA - CVE-2024-47197 - Exposure of Sensitive Information to an...
Exposure of Sensitive Information to an Unauthorized Actor, Insecure Storage of Sensitive Information vulnerability in Maven Archetype Plugin. This issue affects Maven Archetype Plugin: from 3.2.1...
NA - CVE-2024-8861 - The ProfileGrid – User Profiles, Groups and...
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.9.3.2 due to incorrect use of the...
NA - CVE-2024-47044 - Multiple Home GateWay/Hikari Denwa routers...
Multiple Home GateWay/Hikari Denwa routers provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION are vulnerable to insufficient access restrictions for Device Setting pages. If this...
Medium - CVE-2024-8872 - The Store Hours for WooCommerce plugin for...
The Store Hours for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to,...
Medium - CVE-2024-9025 - The Sight – Professional Image Gallery and...
The Sight – Professional Image Gallery and Portfolio plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handler_post_title'...
High - CVE-2022-4541 - The WordPress Visitors plugin for WordPress is...
The WordPress Visitors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a spoofed HTTP Header value in versions up to, and including, 1.0 due to insufficient input sanitization...
Medium - CVE-2024-9115 - The Common Tools for Site plugin for WordPress...
The Common Tools for Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.2 due to insufficient input sanitization...
Medium - CVE-2024-9117 - The Mapplic Lite plugin for WordPress is...
The Mapplic Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0 due to insufficient input sanitization and output...
Medium - CVE-2024-9125 - The king_IE plugin for WordPress is vulnerable...
The king_IE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0 due to insufficient input sanitization and output...