5.7
CVE-2024-8044 - infolinks Ad Wrap <= 1.0.2 - Settings Update via CSRF
The infolinks Ad Wrap WordPress plugin through 1.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
5.7
CVE-2024-8043 - Vikinghammer Tweet <= 0.2.4 - Stored XSS via CSRF
The Vikinghammer Tweet WordPress plugin through 0.2.4 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
5.7
CVE-2024-5170 - Logo Manager For Enamad <= 0.7.1 - Admin+ Stored XSS via Widget
The Logo Manager For Enamad WordPress plugin through 0.7.1 does not sanitise and escape in its widgets settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
7.5
CVE-2024-8110 -
Denial of Service (DoS) vulnerability has been found in Dual-redundant Platform for Computer. If a computer on which the affected product is installed receives a large number of UDP broadcast packets in a short period, occasionally that computer may restart. If both the active and standby computersβ¦
4.4
CVE-2024-45770 - Pcp: pmpost symlink attack allows escalating pcp to root user
A vulnerability was found in Performance Co-Pilot (PCP). This flaw can only be exploited if an attacker has access to a compromised PCP system account. The issue is related to the pmpost tool, which is used to log messages in the system. Under certain conditions, it runs with high-level privileges.
8.2
CVE-2024-47049 -
The czim/file-handling package before 1.5.0 and 2.x before 2.3.0 (used with PHP Composer) does not properly validate URLs within makeFromUrl and makeFromAny, leading to SSRF, and to directory traversal for the reading of local files.
7.5
CVE-2024-47047 -
An issue was discovered in the powermail extension through 12.4.0 for TYPO3. It fails to validate the mail parameter of the createAction, resulting in Insecure Direct Object Reference (IDOR) in some configurations. An unauthenticated attacker can use this to display user-submitted data of all formsβ¦
5.5
CVE-2024-45769 - Pcp: pmcd heap corruption through metric pmstore operations
A vulnerability was found in Performance Co-Pilot (PCP).Β This flaw allows an attacker to send specially crafted data to the system, which could cause the program to misbehave or crash.
6.2
CVE-2024-8939 - Vllm: denials of service in vllm json web api
A vulnerability was found in the ilab model serve component, where improper handling of the best_of parameter in the vllm JSON web API can lead to a Denial of Service (DoS). The API used for LLM-based sentence or chat completion accepts a best_of parameter to return the best completion from severalβ¦
8.8
CVE-2024-46085 -
FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/rename