4.2
CVE-2023-38009 - IBM Cognos Analytics Mobile information disclosure
IBM Cognos Mobile Client 1.1 iOS may be vulnerable to information disclosure through man in the middle techniques due to the lack of certificate pinning.
6.5
CVE-2023-50946 - IBM Common Licensing information disclosure
IBM Common Licensing 9.0 could allow an authenticated user to modify a configuration file that they should not have access to due to a broken authorization mechanism.
6.2
CVE-2023-50945 - IBM Common Licensing information disclosure
IBM Common Licensing 9.0 stores user credentials in plain clear text which can be read by a local user.
6.2
CVE-2024-31906 - IBM Automation Decision Services information disclosure
IBM Automation Decision Services 23.0.2 allows web pages to be stored locally which can be read by another user on the system.
5.5
CVE-2024-13505 - Survey Maker <= 5.1.3.3 - Authenticated (Admin+) Stored Cross-Site Scripting via Survey Question
The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the βays_sections[5][questions][8][title]β parameter in all versions up to, and including, 5.1.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wβ¦
6.1
CVE-2024-12334 - WC Affiliate β A Complete WooCommerce Affiliate Plugin <= 2.4 - Reflected Cross-Site Scripting
The WC Affiliate β A Complete WooCommerce Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via any parameter in all versions up to, and including, 2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackerβ¦
8.8
CVE-2024-11641 - VikBooking Hotel Booking Engine & PMS <= 1.7.2 - Cross-Site Request Forgery to Authenticated (Subscβ¦
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.2. This is due to missing or incorrect nonce validation on the 'save' function. This makes it possible for unauthenticated attackers to change plugin β¦
8.8
CVE-2024-11936 - Zox News <= 3.16.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update
The Zox News theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'backup_options' and 'restore_options' function in all versions up to, and including, 3.16.0. This makes it possible for authenticated aβ¦
5.4
CVE-2024-10705 - Multiple Page Generator Plugin β MPG <= 4.0.5 - Authenticated (Editor+) Server-Side Request Forgeryβ¦
The Multiple Page Generator Plugin β MPG plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.5 via the 'mpg_download_file_by_link' function. This makes it possible for authenticated attackers, with editor-level access and above, to make web reβ¦
5.3
CVE-2024-11090 - Membership Plugin β Restrict Content <= 3.2.13 - Unauthenticated Content Restriction Bypass to Sensβ¦
The Membership Plugin β Restrict Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.13 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been β¦