NA - CVE-2024-45400 - ckeditor-plugin-openlink is a plugin for the...
ckeditor-plugin-openlink is a plugin for the CKEditor JavaScript text editor that extends the context menu with a possibility to open a link in a new tab. A vulnerability in versions of the plugin...
NA - CVE-2024-44082 - In OpenStack Ironic before 26.0.1 and...
In OpenStack Ironic before 26.0.1 and ironic-python-agent before 9.13.1, there is a vulnerability in image processing, in which a crafted image could be used by an authenticated user to exploit...
NA - CVE-2024-40865 - The issue was addressed by suspending Persona...
The issue was addressed by suspending Persona when the virtual keyboard is active. This issue is fixed in visionOS 1.3. Inputs to the virtual keyboard may be inferred from Persona.
Medium - CVE-2024-7415 - The Remember Me Controls plugin for WordPress...
The Remember Me Controls plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0.1. This is due to the plugin allowing direct access to the...
High - CVE-2024-8247 - The Newsletters plugin for WordPress is...
The Newsletters plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.9.9.2. This is due to the plugin not restricting what user meta can be updated as...
NA - CVE-2024-8480 - The Image Optimizer, Resizer and CDN – Sirv...
The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'sirv_save_prevented_sizes'...
NA - CVE-2024-8439 - Rejected reason: Rejected reason: DO NOT USE...
Rejected reason: Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that the issue does not pose a...