5.3
CVE-2024-35670 - WordPress Integrate Google Drive plugin <= 1.3.93 - Broken Access Control vulnerability
Broken Authentication vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.93.
6.5
CVE-2024-34759 - WordPress Picture Gallery plugin <= 1.5.11 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in VideoWhisper Picture Gallery allows Stored XSS.This issue affects Picture Gallery: from n/a through 1.5.11.
7.5
CVE-2024-35672 - WordPress Netgsm plugin <= 2.9.19 - Broken Access Control vulnerability
Missing Authorization vulnerability in Netgsm.This issue affects Netgsm: from n/a through 2.9.19.
7.5
CVE-2024-25095 - WordPress Easy Forms for Mailchimp plugin <= 6.9.0 - Sensitive Data Exposure via Log File vulnerabiβ¦
Insertion of Sensitive Information into Log File vulnerability in Code Parrots Easy Forms for Mailchimp.This issue affects Easy Forms for Mailchimp: from n/a through 6.9.0.
9.8
CVE-2024-37273 -
An arbitrary file upload vulnerability in the /v1/app/appendFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading a crafted file.
9.8
CVE-2024-36858 -
An arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading a crafted file.
7.5
CVE-2024-36857 -
Jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface.
9.8
CVE-2024-36604 -
Tenda O3V2 v1.0.0.12(3880) was discovered to contain a Blind Command Injection via stpEn parameter in the SetStp function. This vulnerability allows attackers to execute arbitrary commands with root privileges.
7.1
CVE-2024-29004 - SolarWinds Platform Stored XSS Vulnerability
The SolarWinds Platform was determined to be affected by a stored cross-site scripting vulnerability affecting the web console. A high-privileged user and user interaction is required to exploit this vulnerability.
6.4
CVE-2024-28999 - SolarWinds Platform Race Condition Vulnerability
The SolarWinds Platform was determined to be affected by a Race Condition Vulnerability affecting the web console.