8.8
CVE-2024-23938 - Silicon Labs Gecko OS Debug Interface Stack-based Buffer Overflow Remote Code Execution Vulnerabiliโฆ
Silicon Labs Gecko OS Debug Interface Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. Thโฆ
6.1
CVE-2024-8715 - Simple LDAP Login <= 1.6.0 - Reflected Cross-Site Scripting
The Simple LDAP Login plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.6.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pagโฆ
5.3
CVE-2024-9189 - EU/UK VAT Manager for WooCommerce <= 2.12.12 - Missing Authorization
The EU/UK VAT Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the alg_wc_eu_vat_exempt_vat_from_admin() function in all versions up to, and including, 2.12.12. This makes it possible for unauthenticated attackers tโฆ
9.8
CVE-2024-8353 - GiveWP โ Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection
The GiveWP โ Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.16.1 via deserialization of untrusted input via several parameters like 'give_title' and 'card_address'. This makes it possible for unauthenticateโฆ
6.4
CVE-2024-9023 - WP-WebAuthn <= 1.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via wwa_login_form โฆ
The WP-WebAuthn plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wwa_login_form shortcode in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated atโฆ
6.1
CVE-2024-8788 - EU/UK VAT Manager for WooCommerce <= 2.12.12 - Reflected Cross-Site Scripting
The EU/UK VAT Manager for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.12.11. This makes it possible for unauthenticated attackers to inject arbitrary โฆ
6.4
CVE-2024-8547 - Simple Popup Plugin <= 4.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
The Simple Popup Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [popup] shortcode in all versions up to, and including, 4.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attโฆ
5.9
CVE-2024-38796 - Integer overflow in PeCoffLoaderRelocateImage
EDK2 contains a vulnerability in the PeCoffLoaderRelocateImage(). An Attacker may cause memory corruption due to an overflow via an adjacent network. A successful exploit of this vulnerability may lead to a loss of Confidentiality, Integrity, and/or Availability.
5.3
CVE-2024-9294 - dingfanzu CMS saveNewPwd.php sql injection
A vulnerability, which was classified as critical, has been found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. Affected by this issue is some unknown functionality of the file saveNewPwd.php. The manipulation of the argument username leads to sql injection. The attack may be lauโฆ
5.3
CVE-2024-23586 - An insufficient session timeout vulnerability affects HCL Nomad server on Domino
HCL Nomad is susceptible to an insufficient session expiration vulnerability. ย Under certain circumstances, an unauthenticated attacker could obtain old session information.