7.5
CVE-2024-4844 -
Hardcoded credentials vulnerability in Trellix ePolicy Orchestrator (ePO) on Premise prior to 5.10 Service Pack 1 Update 2 allows an attacker with admin privileges on the ePO server to read the contents of the orion.keystore file, allowing them to access the ePO database encryption key. This was pβ¦
4.3
CVE-2024-4843 -
ePO doesn't allow a regular privileged user to delete tasks or assignments. Insecure direct object references that allow a least privileged user to manipulate the client task and client task assignments, hence escalating his/her privilege.
5.3
CVE-2024-4961 - D-Link DAR-7000-40 onlineuser.php unrestricted upload
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical was found in D-Link DAR-7000-40 V31R02B1413C. Affected by this vulnerability is an unknown functionality of the file /user/onlineuser.php. The manipulation of the argument file_upload leads to unrestricted upload. The attack canβ¦
4.8
CVE-2024-3644 - Newsletter Popup <= 1.2 - Admin+ Stored XSS
The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
8.8
CVE-2024-3643 - Newsletter Popup <= 1.2 - List Deletion via CSRF
The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting list, which could allow attackers to make logged in admins perform such action via a CSRF attack
6.9
CVE-2024-3642 - Newsletter Popup <= 1.2 - Subscriber Deletion via CSRF
The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting subscriber, which could allow attackers to make logged in admins perform such action via a CSRF attack
6.1
CVE-2024-3641 - Newsletter Popup <= 1.2 - Unauthenticated Stored XSS
The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some parameters, which could allow unauthenticated visitors to perform Cross-Site Scripting attacks against admins
8.8
CVE-2024-4318 - Tutor LMS <= 2.7.0 - Authenticated (Instructor+) SQL Injection
The Tutor LMS plugin for WordPress is vulnerable to time-based SQL Injection via the βquestion_idβ parameter in versions up to, and including, 2.7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for β¦
6.4
CVE-2024-4635 - Menu Icons by ThemeIsle <= 0.13.13 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Upβ¦
The Menu Icons by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the βadd_mime_typeβ function in versions up to, and including, 0.13.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level β¦
6.5
CVE-2024-4279 - Tutor LMS β eLearning and online course solution <= 2.7.0 - Authenticated (Instructor+) Insecure Diβ¦
The Tutor LMS β eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference to Arbitrary Course Deletion in versions up to, and including, 2.7.0 via the 'tutor_course_delete' function due to missing validation on a user controlled key. This can allow β¦