7.8
CVE-2022-49038 -
Inclusion of functionality from untrusted control sphere vulnerability in OpenSSL DLL component in Synology Drive Client before 3.3.0-15082 allows local users to execute arbitrary code via unspecified vectors.
6.5
CVE-2022-49037 -
Insertion of sensitive information into log file vulnerability in proxy settings component in Synology Drive Client before 3.3.0-15082 allows remote authenticated users to obtain sensitive information via unspecified vectors.
8.2
CVE-2023-52946 -
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in vss service component in Synology Drive Client before 3.5.0-16084 allows remote attackers to overwrite trivial buffers and crash the client via unspecified vectors.
4.3
CVE-2024-47330 - Broken Access Control vulnerability on multiple WordPress plugins by Supsystic
Missing Authorization vulnerability in Supsystic Slider by Supsystic, Supsystic Social Share Buttons by Supsystic.This issue affects Slider by Supsystic: from n/a through 1.8.6; Social Share Buttons by Supsystic: from n/a through 2.2.9.
6.1
CVE-2024-8803 - Bulk NoIndex & NoFollow Toolkit <= 2.15 - Reflected Cross-Site Scripting
The Bulk NoIndex & NoFollow Toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.15. This makes it possible for unauthenticated attackers to inject arbitrary weβ¦
4.3
CVE-2024-8552 - Download Monitor <= 5.0.9 - Missing Authorization to Authenticated (Subscriber+) Shop Enable
The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enable_shop() function in all versions up to, and including, 5.0.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enβ¦
6.4
CVE-2024-8723 - 012 PS Multi Languages <= 1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
The 012 Ps Multi Languages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via translated titles in all versions up to, and including, 1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access β¦
7.8
CVE-2024-8404 - Arbitrary File Deletion in PaperCut NG/MF Web Print Hot folder
An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first obtain local login access to the Windows Server hosting PaperCut NG/MF and be capable of executing low-privilege coβ¦
6.1
CVE-2024-8405 - Arbitrary File Creation in PaperCut NG/MF Web Print leading to a Denial of Service attack
An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabled. This specific flaw exists within the web-print.exe process, which can incorrectly create files that donβt exist when a maliciously formed payload is provided. This can be usedβ¦
9.1
CVE-2024-46627 -
Incorrect access control in BECN DATAGERRY v2.2 allows attackers to execute arbitrary commands via crafted web requests.