5.9
CVE-2024-5813 - SSH Private Key Leak in BeyondInsight PasswordSafe
A medium severity vulnerability in BIPS has been identified where an authenticated attacker with high privileges can access the SSH private keys via an information leak in the server response.
5.3
CVE-2024-23521 - WordPress Happyforms plugin <= 1.25.10 - Broken Access Control vulnerability
Missing Authorization vulnerability in Happyforms.This issue affects Happyforms: from n/a through 1.25.10.
5.3
CVE-2023-51682 - WordPress MC4WP plugin <= 4.9.9 - Broken Access Control vulnerability
Missing Authorization vulnerability in ibericode MC4WP.This issue affects MC4WP: from n/a through 4.9.9.
5.3
CVE-2024-34822 - WordPress weMail plugin <= 1.14.2 - Broken Access Control vulnerability
Missing Authorization vulnerability in weDevs weMail.This issue affects weMail: from n/a through 1.14.2.
6.3
CVE-2024-34826 - WordPress CF7 WOW Styler plugin <= 1.6.4 - Broken Access Control vulnerability
Missing Authorization vulnerability in Saleswonder Team: Tobias CF7 WOW Styler cf7-styler.This issue affects CF7 WOW Styler: from n/a through <= 1.6.4.
6.5
CVE-2024-34820 - WordPress If-So Dynamic Content Personalization plugin <= 1.7.1 - Broken Access Control vulnerabiliβ¦
Missing Authorization vulnerability in If So Plugin If-So Dynamic Content Personalization.This issue affects If-So Dynamic Content Personalization: from n/a through 1.7.1.
8.6
CVE-2024-24703 - WordPress MultiVendorX plugin <= 4.0.25 - Broken Access Control vulnerability
Missing Authorization vulnerability in MultiVendorX WC Marketplace.This issue affects WC Marketplace: from n/a through 4.0.25.
4.3
CVE-2024-32148 - WordPress Pardot plugin <= 2.1.0 - Broken Access Control vulnerability
Missing Authorization vulnerability in Salesforce Pardot.This issue affects Pardot: from n/a through 2.1.0.
5.3
CVE-2024-37296 - Aimeos HTML client vulnerable to digital products download without proper payment status check
The Aimeos HTML client provides Aimeos HTML components for e-commerce projects. Starting in version 2020.04.1 and prior to versions 2020.10.27, 2021.10.21, 2022.10.12, 2023.10.14, and 2024.04.5, digital downloads sold in online shops can be downloaded without valid payment, e.g. if the payment didnβ¦
4.3
CVE-2024-35168 - WordPress WP Discourse plugin <= 2.5.1 - Broken Access Control vulnerability
Missing Authorization vulnerability in Discourse WP Discourse.This issue affects WP Discourse: from n/a through 2.5.1.