NA - CVE-2024-37381 - An unspecified SQL Injection vulnerability in...
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2024 flat allows an authenticated attacker within the same network to execute arbitrary code.
NA - CVE-2024-41637 - RaspAP before 3.1.5 allows an attacker to...
RaspAP before 3.1.5 allows an attacker to escalate privileges: the www-data user has write access to the restapi.service file and also possesses Sudo privileges to execute several critical commands...
NA - CVE-2024-4483 - The Email Encoder WordPress plugin before...
The Email Encoder WordPress plugin before 2.2.2 does not escape the WP_Email_Encoder_Bundle_options[protection_text] parameter before outputting it back in an attribute in an admin page, leading...
NA - CVE-2024-5285 - The wp-affiliate-platform WordPress plugin...
The wp-affiliate-platform WordPress plugin before 6.5.2 does not have CSRF check in place when deleting affiliates, which could allow attackers to make a logged in user change delete them via a...
NA - CVE-2024-5882 - The Ultimate Classified Listings WordPress...
The Ultimate Classified Listings WordPress plugin before 1.3 does not validate the `ucl_page` and `layout` parameters allowing unauthenticated users to access PHP files on the server from the...
NA - CVE-2024-5883 - The Ultimate Classified Listings WordPress...
The Ultimate Classified Listings WordPress plugin before 1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could...
NA - CVE-2024-6362 - The Ultimate Blocks WordPress plugin before...
The Ultimate Blocks WordPress plugin before 3.2.0 does not validate and escape some of its post-grid block attributes before outputting them back in a page/post where the block is embed, which...
NA - CVE-2024-6366 - The User Profile Builder WordPress plugin...
The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via the async upload functionality of WP.
NA - CVE-2024-6487 - The Inline Related Posts WordPress plugin...
The Inline Related Posts WordPress plugin before 3.8.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting...
NA - CVE-2024-7185 - A vulnerability was found in TOTOLINK A3600R...
A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102 and classified as critical. Affected by this issue is the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi. The...