6.5
CVE-2024-49270 - WordPress Smart Blocks plugin <= 2.0 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hashthemes Smart Blocks smart-blocks allows Stored XSS.This issue affects Smart Blocks: from n/a through <= 2.0.
6.4
CVE-2023-32189 - Insecure handling SSH key in SUSE Manager when bootstrapping new clients
Insecure handling of ssh keys used to bootstrap clients allows local attackers to potentially gain access to the keys
5.3
CVE-2024-49252 - WordPress leyka plugin <=3.31.6 - Broken Access Control vulnerability
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in VaultDweller Leyka leyka.This issue affects Leyka: from n/a through <= 3.31.6.
0.0
CVE-2024-49245 - WordPress Ahime Image Printer plugin <= 1.0.0 - Arbitrary File Download vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in nahimsalami Ahime Image Printer ahime-image-printer.This issue affects Ahime Image Printer: from n/a through <= 1.0.0.
5.5
CVE-2024-22034 - Crafted projects can overwrite special files in the .osc config directory
Attackers could put the special files in .osc into the actual package sources (e.g. _apiurl). This allows the attacker to change the configuration of osc for the victim
6.5
CVE-2024-49258 - WordPress Limb Gallery plugin <= 1.5.7 - Arbitrary File Download vulnerability
Path Traversal: '.../...//' vulnerability in Limbcode WordPress Gallery Plugin โ Limb Image Gallery limb-gallery.This issue affects WordPress Gallery Plugin โ Limb Image Gallery: from n/a through <= 1.5.7.
9.9
CVE-2024-48034 - WordPress Creates 3D Flipbook, PDF Flipbook plugin <= 1.2 - Arbitrary File Upload vulnerability
Unrestricted Upload of File with Dangerous Type vulnerability in fliperrr Creates 3D Flipbook, PDF Flipbook create-flipbook-from-pdf allows Upload a Web Shell to a Web Server.This issue affects Creates 3D Flipbook, PDF Flipbook: from n/a through <= 1.2.
5.1
CVE-2024-22033 - obs-service-download_url is vulnerable to argument injection
The OBS service obs-service-download_url was vulnerable to a command injection vulnerability. The attacker could provide a configuration to the service that allowed to execute command in later steps
0.0
CVE-2024-49216 - WordPress Feed Comments Number plugin <= 0.2.1 - Arbitrary File Upload vulnerability
Unrestricted Upload of File with Dangerous Type vulnerability in jclay06 Feed Comments Number feed-comments-number allows Upload a Web Shell to a Web Server.This issue affects Feed Comments Number: from n/a through <= 0.2.1.
0.0
CVE-2024-49242 - WordPress Digital Lottery plugin <= 3.0.5 - Arbitrary File Upload vulnerability
Unrestricted Upload of File with Dangerous Type vulnerability in Shafiq Digital Lottery digital-lottery allows Upload a Web Shell to a Web Server.This issue affects Digital Lottery: from n/a through <= 3.0.5.