Latest CVE Feed
-
6.3
MEDIUMCVE-2024-8254
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.7.34. This is due to the software a... Read more
Affected Products : email_subscribers_\&_newsletters- Published: Oct. 02, 2024
- Modified: Oct. 08, 2024
-
6.1
MEDIUMCVE-2024-8800
The RabbitLoader – Website Speed Optimization for improving Core Web Vital metrics with Cache, Image Optimization, and more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping o... Read more
Affected Products : rabbitloader- Published: Oct. 02, 2024
- Modified: Oct. 08, 2024
-
6.1
MEDIUMCVE-2024-9353
The Popularis Extra plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.2.6. This makes it possible for una... Read more
Affected Products : popularis_extra- Published: Oct. 04, 2024
- Modified: Oct. 08, 2024
-
6.4
MEDIUMCVE-2024-8967
The PWA — easy way to Progressive Web App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6.3 due to insufficient input sanitization and output escaping. This makes it possible... Read more
Affected Products : pwa- Published: Oct. 02, 2024
- Modified: Oct. 08, 2024
-
9.8
CRITICALCVE-2024-9574
SQL injection vulnerability in SOPlanning <1.45, via /soplanning/www/user_groupes.php in the by parameter, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.... Read more
Affected Products : soplanning- Published: Oct. 07, 2024
- Modified: Oct. 08, 2024
-
6.5
MEDIUMCVE-2024-9573
SQL injection vulnerability in SOPlanning <1.45, through /soplanning/www/groupe_list.php, in the by parameter, which could allow a remote user to send a specially crafted query and extract all the information stored on the server.... Read more
Affected Products : soplanning- Published: Oct. 07, 2024
- Modified: Oct. 08, 2024
-
6.3
MEDIUMCVE-2024-9572
Cross-Site Scripting (XSS) vulnerability in SOPlanning <1.45, due to lack of proper validation of user input via /soplanning/www/process/groupe_save.php, in the groupe_id parameter. This could allow a remote user to send a specially crafted query to an au... Read more
Affected Products : soplanning- Published: Oct. 07, 2024
- Modified: Oct. 08, 2024
-
6.3
MEDIUMCVE-2024-9571
Cross-Site Scripting (XSS) vulnerability in SOPlanning <1.45, due to lack of proper validation of user input via /soplanning/www/process/xajax_server.php, affecting multiple parameters. This could allow a remote user to send a specially crafted query to a... Read more
Affected Products : soplanning- Published: Oct. 07, 2024
- Modified: Oct. 08, 2024
-
9.0
HIGHCVE-2024-9565
A vulnerability has been found in D-Link DIR-605L 2.13B01 BETA and classified as critical. Affected by this vulnerability is the function formSetPassword of the file /goform/formSetPassword. The manipulation of the argument curTime leads to buffer overflo... Read more
- Published: Oct. 07, 2024
- Modified: Oct. 08, 2024
-
9.0
HIGHCVE-2024-9564
A vulnerability, which was classified as critical, was found in D-Link DIR-605L 2.13B01 BETA. Affected is the function formWlanWizardSetup of the file /goform/formWlanWizardSetup. The manipulation of the argument webpage leads to buffer overflow. It is po... Read more
- Published: Oct. 07, 2024
- Modified: Oct. 08, 2024
-
9.0
HIGHCVE-2024-9563
A vulnerability, which was classified as critical, has been found in D-Link DIR-605L 2.13B01 BETA. This issue affects the function formWlanSetup_Wizard of the file /goform/formWlanSetup_Wizard. The manipulation of the argument webpage leads to buffer over... Read more
- Published: Oct. 07, 2024
- Modified: Oct. 08, 2024
-
9.0
HIGHCVE-2024-9562
A vulnerability classified as critical was found in D-Link DIR-605L 2.13B01 BETA. This vulnerability affects the function formSetWizard1/formSetWizard2. The manipulation of the argument curTime leads to buffer overflow. The attack can be initiated remotel... Read more
- Published: Oct. 06, 2024
- Modified: Oct. 08, 2024
-
9.0
HIGHCVE-2024-9561
A vulnerability classified as critical has been found in D-Link DIR-605L 2.13B01 BETA. This affects the function formSetWAN_Wizard51/formSetWAN_Wizard52. The manipulation of the argument curTime leads to buffer overflow. It is possible to initiate the att... Read more
- Published: Oct. 06, 2024
- Modified: Oct. 08, 2024
-
9.0
HIGHCVE-2024-9559
A vulnerability was found in D-Link DIR-605L 2.13B01 BETA. It has been classified as critical. Affected is the function formWlanSetup of the file /goform/formWlanSetup. The manipulation of the argument webpage leads to buffer overflow. It is possible to l... Read more
- Published: Oct. 06, 2024
- Modified: Oct. 08, 2024
-
9.0
HIGHCVE-2024-9557
A vulnerability has been found in D-Link DIR-605L 2.13B01 BETA and classified as critical. This vulnerability affects the function formSetWanPPPoE of the file /goform/formSetWanPPPoE. The manipulation of the argument webpage leads to buffer overflow. The ... Read more
- Published: Oct. 06, 2024
- Modified: Oct. 08, 2024
-
9.0
HIGHCVE-2024-9556
A vulnerability, which was classified as critical, was found in D-Link DIR-605L 2.13B01 BETA. This affects the function formSetEnableWizard of the file /goform/formSetEnableWizard. The manipulation of the argument curTime leads to buffer overflow. It is p... Read more
- Published: Oct. 06, 2024
- Modified: Oct. 08, 2024
-
9.0
HIGHCVE-2024-9558
A vulnerability was found in D-Link DIR-605L 2.13B01 BETA and classified as critical. This issue affects the function formSetWanPPTP of the file /goform/formSetWanPPTP. The manipulation of the argument webpage leads to buffer overflow. The attack may be i... Read more
- Published: Oct. 06, 2024
- Modified: Oct. 08, 2024
-
9.0
HIGHCVE-2024-9555
A vulnerability, which was classified as critical, has been found in D-Link DIR-605L 2.13B01 BETA. Affected by this issue is the function formSetEasy_Wizard of the file /goform/formSetEasy_Wizard. The manipulation of the argument curTime leads to buffer o... Read more
- Published: Oct. 06, 2024
- Modified: Oct. 08, 2024
-
5.5
MEDIUMCVE-2024-46846
In the Linux kernel, the following vulnerability has been resolved: spi: rockchip: Resolve unbalanced runtime PM / system PM handling Commit e882575efc77 ("spi: rockchip: Suspend and resume the bus during NOIRQ_SYSTEM_SLEEP_PM ops") stopped respecting r... Read more
Affected Products : linux_kernel- Published: Sep. 27, 2024
- Modified: Oct. 08, 2024
-
5.5
MEDIUMCVE-2024-46843
In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Remove SCSI host only if added If host tries to remove ufshcd driver from a UFS device it would cause a kernel panic if ufshcd_async_scan fails during ufshcd_probe_hba ... Read more
Affected Products : linux_kernel- Published: Sep. 27, 2024
- Modified: Oct. 08, 2024