NA - CVE-2024-7215 - A vulnerability was found in TOTOLINK LR1200...
A vulnerability was found in TOTOLINK LR1200 9.3.1cu.2832 and classified as critical. Affected by this issue is the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi. The manipulation of...
NA - CVE-2024-7216 - A vulnerability was found in TOTOLINK LR1200...
A vulnerability was found in TOTOLINK LR1200 9.3.1cu.2832. It has been classified as problematic. This affects an unknown part of the file /etc/shadow.sample. The manipulation leads to use of...
NA - CVE-2024-7217 - A vulnerability was found in TOTOLINK CA300-PoE...
A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been declared as critical. This vulnerability affects the function loginauth of the file /cgi-bin/cstecgi.cgi. The manipulation of...
NA - CVE-2024-7218 - A vulnerability was found in SourceCodester...
A vulnerability was found in SourceCodester School Log Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file...
NA - CVE-2024-1286 - The pmpro-membership-maps WordPress plugin...
The pmpro-membership-maps WordPress plugin before 0.7 does not prevent users with at least the contributor role from leaking sensitive information about users with a membership on the site.
NA - CVE-2024-1287 - The pmpro-member-directory WordPress plugin...
The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes.
NA - CVE-2024-3113 - The FormFlow: WhatsApp Social and Advanced Form...
The FormFlow: WhatsApp Social and Advanced Form Builder with Easy Lead Collection WordPress plugin before 2.12.2 does not sanitise and escape some of its settings, which could allow high privilege...
NA - CVE-2024-3669 - The Web Directory Free WordPress plugin before...
The Web Directory Free WordPress plugin before 1.7.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used...
NA - CVE-2024-3986 - The SportsPress WordPress plugin before 2.7.22...
The SportsPress WordPress plugin before 2.7.22 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting...
NA - CVE-2024-4096 - The Responsive Tabs WordPress plugin through...
The Responsive Tabs WordPress plugin through 4.0.8 does not sanitise and escape some of its Tab settings, which could allow high privilege users such as Contributors and above to perform Stored...