NA - CVE-2024-47609 - Tonic is a native gRPC client & server...
Tonic is a native gRPC client & server implementation with async/await support. When using tonic::transport::Server there is a remote DoS attack that can cause the server to exit cleanly on...
Medium - CVE-2024-9407 - A vulnerability exists in the bind-propagation...
A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction. The system does not properly validate the input passed to this option, allowing users to pass...
NA - CVE-2024-3635 - The Post Grid WordPress plugin before 7.5.0...
The Post Grid WordPress plugin before 7.5.0 does not sanitise and escape some of its Grid settings, which could allow high privilege users such as Editor and above to perform Stored Cross-Site...
NA - CVE-2024-8239 - The Starbox WordPress plugin before 3.5.3 does...
The Starbox WordPress plugin before 3.5.3 does not properly render social media profiles URLs in certain contexts, like the malicious user's profile or pages where the starbox shortcode is...
NA - CVE-2024-8283 - The Slider by 10Web WordPress plugin before...
The Slider by 10Web WordPress plugin before 1.2.59 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting...
NA - CVE-2024-8379 - The Cost Calculator Builder WordPress plugin...
The Cost Calculator Builder WordPress plugin before 3.2.29 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with...
NA - CVE-2024-8536 - The Ultimate Blocks WordPress plugin before...
The Ultimate Blocks WordPress plugin before 3.2.2 does not validate and escape some of its block attributes before outputting them back in a page/post where the block is embed, which could allow...