6.3

CVSS3.1

CVE-2024-6444 - Bluetooth: ots: missing buffer length check

No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client.c.

πŸ“… Published: Oct. 4, 2024, 6:14 a.m. πŸ”„ Last Modified: Nov. 13, 2024, 3:24 p.m.

6.3

CVSS3.1

CVE-2024-6443 - zephyr: out-of-bound read in utf8_trunc

In utf8_trunc in zephyr/lib/utils/utf8.c, last_byte_p can point to one byte before the string pointer if the string is empty.

πŸ“… Published: Oct. 4, 2024, 5:56 a.m. πŸ”„ Last Modified: Nov. 12, 2024, 7:29 p.m.

6.3

CVSS3.1

CVE-2024-6442 - Bluetooth: ASCS Unchecked tailroom of the response buffer

In ascs_cp_rsp_add in /subsys/bluetooth/audio/ascs.c, an unchecked tailroom could lead to a global buffer overflow.

πŸ“… Published: Oct. 4, 2024, 5:36 a.m. πŸ”„ Last Modified: Nov. 13, 2024, 4:04 p.m.

6.4

CVSS3.1

CVE-2024-9242 - Memberful – Membership Plugin <= 1.73.7 - Authenticated (contributor+) Stored Cross-Site Scripting

The Memberful – Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'memberful_buy_subscription_link' and 'memberful_podcasts_link' shortcodes in all versions up to, and including, 1.73.7 due to insufficient input sanitization and output escaping on …

πŸ“… Published: Oct. 4, 2024, 5:30 a.m. πŸ”„ Last Modified: April 8, 2026, 5:30 p.m.

6.4

CVSS3.1

CVE-2024-8804 - Code Embed <= 2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Code Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's script embed functionality in all versions up to, and including, 2.4 due to insufficient restrictions on who can utilize the functionality. This makes it possible for authenticated attackers, with cont…

πŸ“… Published: Oct. 4, 2024, 5:30 a.m. πŸ”„ Last Modified: April 8, 2026, 5:14 p.m.

6.1

CVSS3.1

CVE-2024-9237 - Fish and Ships <= 1.5.9 - Reflected Cross-Site Scripting

The Fish and Ships – Most flexible shipping table rate. A WooCommerce shipping rate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.5.9. This makes it possible for un…

πŸ“… Published: Oct. 4, 2024, 2:32 a.m. πŸ”„ Last Modified: April 8, 2026, 5:24 p.m.

6.4

CVSS3.1

CVE-2024-8519 - Ultimate Member <= 2.8.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'um_loggedin' shortcode in all versions up to, and including, 2.8.6 due to insufficient input sanitiz…

πŸ“… Published: Oct. 4, 2024, 2:32 a.m. πŸ”„ Last Modified: April 8, 2026, 5:11 p.m.

5.3

CVSS3.1

CVE-2024-8520 - Ultimate Member <= 2.8.6 - Cross-Site Request Forgery to Membership Status Change

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.6. This is due to missing or incorrect nonce validation on the admin_init or …

πŸ“… Published: Oct. 4, 2024, 2:32 a.m. πŸ”„ Last Modified: April 8, 2026, 5:03 p.m.

6.1

CVSS3.1

CVE-2024-9384 - Quantity Dynamic Pricing & Bulk Discounts for WooCommerce <= 3.8.0 - Reflected Cross-Site Scripting

The Quantity Dynamic Pricing & Bulk Discounts for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.8.0. This makes it possible for unauthenticated attacker…

πŸ“… Published: Oct. 4, 2024, 2:04 a.m. πŸ”„ Last Modified: April 8, 2026, 5:30 p.m.

6.4

CVSS3.1

CVE-2024-9445 - Display Medium Posts <= 5.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via displa…

The Display Medium Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's display_medium_posts shortcode in all versions up to, and including, 5.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for a…

πŸ“… Published: Oct. 4, 2024, 2:04 a.m. πŸ”„ Last Modified: April 8, 2026, 5:19 p.m.
Total resulsts: 349182
Page 8404 of 34,919
Β« previous page Β» next page
Filters