4.3
CVE-2024-9531 - MultiVendorX β The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.4 - Missing Authoriβ¦
The MultiVendorX β The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'mvx_sent_deactivation_request' function in all versions up to, and including, 4.2.4. This makes it possible β¦
6.1
CVE-2024-9864 - EventPrime β Modern Events Calendar, Bookings and Tickets <= 4.0.4.7 - Unauthenticated Stored Crossβ¦
The EventPrime β Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ticket names in all versions up to, and including, 4.0.4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers toβ¦
6.1
CVE-2024-9865 - EventPrime β Modern Events Calendar, Bookings and Tickets <= 4.0.4.7 - Unauthenticated Stored Crossβ¦
The EventPrime β Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the βep_booking_attendee_fieldsβ fields in all versions up to, and including, 4.0.4.7 due to insufficient input sanitization and output escaping. This makes it possible for uβ¦
6.1
CVE-2024-9374 - Terms descriptions <= 3.4.6 - Reflected Cross-Site Scripting
The Terms descriptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.4.6. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in paβ¦
9.1
CVE-2024-48144 -
A prompt injection vulnerability in the chatbox of Fusion Chat Chat AI Assistant Ask Me Anything v1.2.4.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.
7.8
CVE-2024-45242 -
EnGenius ENH1350EXT A8J-ENH1350EXT devices through 3.9.3.2_c1.9.51 allow (blind) OS Command Injection via shell metacharacters to the Ping or Speed Test utility. During the time of initial setup, the device creates an open unsecured network whose admin panel is configured with the default credentiaβ¦
9.8
CVE-2024-48514 -
php-heic-to-jpg <= 1.0.5 is vulnerable to code injection (fixed in 1.0.6). An attacker who can upload heic images is able to execute code on the remote server via the file name. As a result, the CIA is no longer guaranteed. This affects php-heic-to-jpg 1.0.5 and below.
8.4
CVE-2024-48545 -
Incorrect access control in the firmware update and download processes of IVY Smart v4.5.0 allows attackers to access sensitive information by analyzing the code and data within the APK file.
9.8
CVE-2024-48539 -
Neye3C v4.5.2.0 was discovered to contain a hardcoded encryption key in the firmware update mechanism.
9.8
CVE-2024-48538 -
Incorrect access control in the firmware update and download processes of Neye3C v4.5.2.0 allows attackers to access sensitive information by analyzing the code and data within the APK file.