Medium - CVE-2024-2090 - The Remote Content Shortcode plugin for...
The Remote Content Shortcode plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.5 via the remote_content shortcode. This makes it possible for...
NA - CVE-2024-7342 - A vulnerability was found in Baidu UEditor...
A vulnerability was found in Baidu UEditor 1.4.3.3. It has been classified as problematic. This affects an unknown part of the file /ueditor/php/controller.php?action=uploadfile&encode=utf-8. The...
NA - CVE-2024-7343 - A vulnerability was found in Baidu UEditor...
A vulnerability was found in Baidu UEditor 1.4.2. It has been declared as problematic. This vulnerability affects unknown code of the file /ueditor142/php/controller.php?action=catchimage. The...
NA - CVE-2024-1747 - The WooCommerce Customers Manager WordPress...
The WooCommerce Customers Manager WordPress plugin before 30.2 does not have authorisation and CSRF in various AJAX actions, allowing any authenticated users, such as subscriber, to call them and...
NA - CVE-2024-2843 - The WooCommerce Customers Manager WordPress...
The WooCommerce Customers Manager WordPress plugin before 30.1 does not have CSRF checks in some places, which could allow attackers to make logged in admin users delete users via CSRF attacks
NA - CVE-2024-2872 - The socialdriver-framework WordPress plugin...
The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored...
NA - CVE-2024-7212 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, has been found in TOTOLINK A7000R 9.1.0u.6268_B20220504. This issue affects the function loginauth of the file /cgi-bin/cstecgi.cgi. The...
NA - CVE-2024-7213 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, was found in TOTOLINK A7000R 9.1.0u.6268_B20220504. Affected is the function setWizardCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of...
NA - CVE-2024-7214 - A vulnerability has been found in TOTOLINK...
A vulnerability has been found in TOTOLINK LR350 9.3.5u.6369_B20220309 and classified as critical. Affected by this vulnerability is the function setWanCfg of the file /cgi-bin/cstecgi.cgi. The...