5.4
CVE-2024-2640 - Watu Quiz < 3.4.1.2 - Author+ Stored XSS
The Watu Quiz WordPress plugin before 3.4.1.2 does not sanitise and escape some of its settings, which could allow users such as authors (if they've been authorized by admins) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
5.4
CVE-2024-2430 - Website Content in Page or Post < 2024.04.09 - Contributor+ Stored Cross-Site Scripting
The Website Content in Page or Post WordPress plugin before 2024.04.09 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scriβ¦
4.8
CVE-2024-0974 - Social Media Widget < 4.0.9 - Admin+ Stored XSS
The Social Media Widget WordPress plugin before 4.0.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
5.3
CVE-2024-6555 - WP Popups β WordPress Popup builder <= 2.2.0.1 - Unauthenticated Full Path Disclosure
The WP Popups β WordPress Popup builder plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.2.0.1. This is due the plugin utilizing mobiledetect without preventing direct access to the files. This makes it possible for unauthenticated attackers to retrβ¦
7.3
CVE-2024-6677 -
Privilege escalation in uberAgent
4.3
CVE-2024-1375 - Event post <= 5.9.10 - Cross-Site Request Forgery
The Event post plugin for WordPress is vulnerable to unauthorized bulk metadata update due to a missing nonce check on the save_bulkdatas function in all versions up to, and including, 5.9.10. This makes it possible for unauthenticated attackers to update post_meta_data via a forged request, granteβ¦
9.8
CVE-2024-6396 - Arbitrary File Overwrite and Data Exfiltration in aimhubio/aim
A vulnerability in the `_backup_run` function in aimhubio/aim version 3.19.3 allows remote attackers to overwrite any file on the host server and exfiltrate arbitrary data. The vulnerability arises due to improper handling of the `run_hash` and `repo.path` parameters, which can be manipulated to crβ¦
5.5
CVE-2024-40983 - tipc: force a dst refcount before doing decryption
In the Linux kernel, the following vulnerability has been resolved: tipc: force a dst refcount before doing decryption As it says in commit 3bc07321ccc2 ("xfrm: Force a dst refcount before entering the xfrm type handlers"): "Crypto requests might return asynchronous. In this case we leave the rβ¦
7.8
CVE-2024-39502 - ionic: fix use after netif_napi_del()
In the Linux kernel, the following vulnerability has been resolved: ionic: fix use after netif_napi_del() When queues are started, netif_napi_add() and napi_enable() are called. If there are 4 queues and only 3 queues are used for the current configuration, only 3 queues' napi should be registereβ¦
5.5
CVE-2024-40998 - ext4: fix uninitialized ratelimit_state->lock access in __ext4_fill_super()
In the Linux kernel, the following vulnerability has been resolved: ext4: fix uninitialized ratelimit_state->lock access in __ext4_fill_super() In the following concurrency we will access the uninitialized rs->lock: ext4_fill_super ext4_register_sysfs // sysfs registered msg_ratelimit_interβ¦