8.3
CVE-2024-3083 -
A βCWE-352: Cross-Site Request Forgery (CSRF)β can be exploited by remote attackers to perform state-changing operations with administrative privileges by luring authenticated victims into visiting a malicious web page.
4.2
CVE-2024-3082 -
A βCWE-256: Plaintext Storage of a Passwordβ affecting the administrative account allows an attacker with physical access to the machine to retrieve the password in cleartext unless specific security measures at other layers (e.g., full-disk encryption) have been enabled.
5.5
CVE-2024-39379 - Acrobat for Edge | Out-of-bounds Read (CWE-125)
Acrobat for Edge versions 126.0.2592.81 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that aβ¦
6.4
CVE-2024-6208 - Download Manager <= 3.2.97 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_all_packages' shortcode in all versions up to, and including, 3.2.97 due to insufficient input sanitization and output escaping on the 'cols' parameter. This makes it possible for authenticβ¦
6.9
CVE-2024-7321 - itsourcecode Online Blood Bank Management System User Registration signup.php cross site scripting
A vulnerability classified as problematic was found in itsourcecode Online Blood Bank Management System 1.0. This vulnerability affects unknown code of the file signup.php of the component User Registration Handler. The manipulation of the argument user leads to cross site scripting. The attack canβ¦
6.9
CVE-2024-7320 - itsourcecode Online Blood Bank Management System Admin Login index.php sql injection
A vulnerability classified as critical has been found in itsourcecode Online Blood Bank Management System 1.0. This affects an unknown part of the file /admin/index.php of the component Admin Login. The manipulation of the argument user leads to sql injection. It is possible to initiate the attack β¦
6.5
CVE-2024-7135 - Tainacan <= 0.21.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read
The Tainacan plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_file' function in all versions up to, and including, 0.21.7. The function is also vulnerable to directory traversal. This makes it possible for authenticated attackers, with β¦
4.9
CVE-2024-6725 - Formidable Forms <= 6.11.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting
The Formidable Forms β Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the βhtmlβ parameter in all versions up to, and including, 6.11.1 due to insufficient input sanitization and output escapingβ¦
6.9
CVE-2024-7311 - code-projects Online Bus Reservation Site register.php sql injection
A vulnerability was found in code-projects Online Bus Reservation Site 1.0. It has been rated as critical. This issue affects some unknown processing of the file register.php. The manipulation of the argument Email leads to sql injection. The attack may be initiated remotely. The exploit has been dβ¦
5.3
CVE-2024-7310 - SourceCodester Record Management System sort_user.php cross site scripting
A vulnerability was found in SourceCodester Record Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file sort_user.php. The manipulation of the argument sort leads to cross site scripting. The attack can be initiated remotely. The exploit haβ¦