NA - CVE-2024-45232 - An issue was discovered in powermail extension...
An issue was discovered in powermail extension through 12.3.5 for TYPO3. It fails to validate the mail parameter of the confirmationAction, resulting in Insecure Direct Object Reference (IDOR). An...
NA - CVE-2024-45233 - An issue was discovered in powermail extension...
An issue was discovered in powermail extension through 12.3.5 for TYPO3. Several actions in the OutputController can directly be called, due to missing or insufficiently implemented access checks,...
NA - CVE-2024-41918 - 'Rakuten Ichiba App' for Android...
'Rakuten Ichiba App' for Android 12.4.0 and earlier and 'Rakuten Ichiba App' for iOS 11.7.0 and earlier are vulnerable to improper authorization in handler for custom URL...
Critical - CVE-2024-7857 - The Media Library Folders plugin for WordPress...
The Media Library Folders plugin for WordPress is vulnerable to second order SQL Injection via the 'sort_type' parameter of the 'mlf_change_sort_type' AJAX action in all...
NA - CVE-2021-4442 - In the Linux kernel, the following...
In the Linux kernel, the following vulnerability has been resolved: tcp: add sanity tests to TCP_QUEUE_SEQ Qingyu Li reported a syzkaller bug where the repro changes RCV SEQ _after_ restoring...
High - CVE-2022-2440 - The Theme Editor plugin for WordPress is...
The Theme Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'images_array' parameter in versions up to, and including 2.8. This makes it possible for...
NA - CVE-2024-29723 - SQL injection vulnerabilities in SportsNET...
SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a...