7.3
CVE-2024-10633 - Quiz Maker Business, Developer, and Agency <= (Multiple Versions) - Unauthenticated Arbitrary Short…
The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), and up to, and including, 31.8.0 (Agency). This is due to the software allowing users…
7.2
CVE-2024-10574 - Quiz Maker Business, Developer, and Agency <= (Multiple Versions) - Missing Authorization to Google…
The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ays_save_google_credentials' function in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), a…
7.5
CVE-2024-10628 - Quiz Maker Business, Developer, and Agency <= (Multiple Versions) - Unauthenticated SQL Injection v…
The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), and up to, and including, 31.8.0 (Agency) due to insufficient escaping on the …
6.1
CVE-2024-10636 - Quiz Maker Business, Developer, and Agency <= (Multiple Versions) - Reflected DOM-Based Cross-Site…
The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), and up to, and including, 31.8.0 (Agency) due to insuffi…
8.1
CVE-2022-49043 - libxml: use-after-free in xmlXIncludeAddNode
xmlXIncludeAddNode in xinclude.c in libxml2 before 2.11.0 has a use-after-free.
7.1
CVE-2024-46881 -
Develocity (formerly Gradle Enterprise) before 2024.1.8 has Incorrect Access Control. Project-level access control configuration was introduced in Enterprise Config schema version 8. Migration functionality from schema version 8 to versions 9 and 10 (in affected vulnerable versions) does not includ…
8.3
CVE-2025-24858 -
Develocity (formerly Gradle Enterprise) before 2024.3.1 allows an attacker who has network access to a Develocity server to obtain the hashed password of the system user. The hash algorithm used by Develocity was chosen according to best practices for password storage and provides some protection a…
8.5
CVE-2025-0543 - G DATA Security Client Local privilege escalation
Local privilege escalation in G DATA Security Client due to incorrect assignment of privileges to directories. This vulnerability allows a local, unprivileged attacker to escalate privileges on affected installations by placing an arbitrary executable in a globally writable directory resulting in e…
7.3
CVE-2025-0542 - G DATA Management Server Local privilege escalation
Local privilege escalation due to incorrect assignment of privileges of temporary files in the update mechanism of G DATA Management Server. This vulnerability allows a local, unprivileged attacker to escalate privileges on affected installations by placing a crafted ZIP archive in a globally writa…
5.3
CVE-2024-35150 - IBM Maximo Application Suite log manipulation
IBM Maximo Application Suite 8.10.12, 8.11.0, 9.0.1, and 9.1.0 - Monitor Component does not neutralize output that is written to logs, which could allow an attacker to inject false log entries.