3.8
CVE-2024-3628 - EasyEvent <= 1.0.0 - Admin+ Stored XSS
The EasyEvent WordPress plugin through 1.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
9.8
CVE-2024-4186 - Edwiser Bridge <= 3.0.5 - Authentication Bypass due to Missing Empty Value Check
The Edwiser Bridge plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.0.5. This is due to the 'eb_user_email_verification_key' default value is empty, and the not empty check is missing in the 'eb_user_email_verify' function. This makes it possible for uβ¦
8.1
CVE-2024-22472 - Long S0 frames received by 500 series Z-Wave devices may cause buffer overflow
A buffer Overflow vulnerability in Silicon Labs 500 Series Z-Wave devices may allow Denial of Service, and potential Remote Code execution This issue affects all versions of Silicon LabsΒ 500 Series SDK prior to v6.85.2 running on Silicon Labs 500 series Z-wave devices.
2.4
CVE-2024-20855 -
Improper access control vulnerability in multitasking framework prior to SMR May-2024 Release 1 allows physical attackers to access unlocked screen for a while.
6.2
CVE-2024-20872 -
Improper handling of insufficient privileges vulnerability in TalkbackSE prior to version Android 14 allows local attackers to modify setting value of TalkbackSE.
4.9
CVE-2024-20871 -
Improper authorization vulnerability in Samsung Keyboard prior to version One UI 5.1.1 allows physical attackers to partially bypass the factory reset protection.
5.1
CVE-2024-20870 -
Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.71.8 allows local attackers to write arbitrary files with the privilege of Galaxy Store.
5.5
CVE-2024-20869 -
Improper privilege management vulnerability in Samsung Internet prior to version 25.0.0.41 allows local attackers to bypass protection for cookies.
4.4
CVE-2024-20868 -
Improper input validation in Samsung Notes prior to version 4.4.15 allows local attackers to delete files with Samsung Notes privilege under certain conditions.
5.5
CVE-2024-20867 -
Improper privilege management vulnerability in Samsung Email prior to version 6.1.91.14 allows local attackers to access sensitive information.