5.4
CVE-2024-35663 - WordPress WP Translate plugin <= 5.3.0 - Broken Access Control vulnerability
Missing Authorization vulnerability in HahnCreativeGroup WP Translate.This issue affects WP Translate: from n/a through 5.3.0.
5.5
CVE-2024-37294 - Aimeos denial of service vulnerability in SaaS and marketplace setups
Aimeos is an Open Source e-commerce framework for online shops. All SaaS and marketplace setups using Aimeos version from 2022/2023/2024 are affected by a potential denial of service attack. Users should upgrade to versions 2022.10.17, 2023.10.17, or 2024.04 of the aimeos/aimeos-core package to recβ¦
6.5
CVE-2023-52199 - WordPress ActivityPub plugin <= 1.0.5 - Unauthenticated Broken Access Control vulnerability
Missing Authorization vulnerability in Matthias Pfefferle & Automattic ActivityPub.This issue affects ActivityPub: from n/a through 1.0.5.
5.3
CVE-2024-35665 - WordPress Insert Post Ads plugin <= 1.3.2 - Broken Access Control vulnerability
Missing Authorization vulnerability in namithjawahar Insert Post Ads.This issue affects Insert Post Ads: from n/a through 1.3.2.
5.3
CVE-2024-35667 - WordPress Shopping Cart & eCommerce Store plugin <= 5.5.19 - Broken Access Control vulnerability
Missing Authorization vulnerability in WP EasyCart.This issue affects WP EasyCart: from n/a through 5.5.19.
4
CVE-2024-37161 - MeterSphere front-end editor stores XSS vulnerability
MeterSphere is an open source continuous testing platform. Prior to version 1.10.1-lts, the system's step editor stores cross-site scripting vulnerabilities. Version 1.10.1-lts fixes this issue.
4.4
CVE-2024-35235 - Cupsd Listen arbitrary chmod 0140777
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.8 and earlier, when starting the cupsd server with a Listen configuration item pointing to a symbolic link, the cupsd process can be caused to perform an arbitrary chmod of the proviβ¦
5.7
CVE-2024-28023 -
A vulnerability exists in the message queueing mechanism that if exploited can lead to the exposure of resources or functionality to unintended actors, possibly providing attackers with sensitive information or even execute arbitrary code.
6.4
CVE-2024-5189 - Essential Addons for Elementor β Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= β¦
The Essential Addons for Elementor β Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the βcustom_jsβ parameter in all versions up to, and including, 5.9.23 due to insufficient input sanitization and output escapingβ¦
4.3
CVE-2024-35671 - WordPress MJ Update History plugin <= 1.0.4 - Broken Access Control vulnerability
Missing Authorization vulnerability in Minoji MJ Update History.This issue affects MJ Update History: from n/a through 1.0.4.