CVE-2024-12819 |
Description: The Searchie plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sio_embed_media' shortcode in all versions up to, and including, 1.17.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVSS: MEDIUM (6.4) EPSS Score: 0.05%
January 10th, 2025 (6 months ago)
|
CVE-2024-12806 |
Description: A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an arbitrary file.
CVSS: MEDIUM (4.9) EPSS Score: 0.04%
January 10th, 2025 (6 months ago)
|
CVE-2024-12805 |
Description: A post-authentication format string vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution.
CVSS: HIGH (7.2) EPSS Score: 0.04%
January 10th, 2025 (6 months ago)
|
CVE-2024-12803 |
Description: A post-authentication stack-based buffer overflow vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution.
CVSS: HIGH (7.2) EPSS Score: 0.04%
January 10th, 2025 (6 months ago)
|
CVE-2024-12802 |
Description: SSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling of UPN (User Principal Name) and SAM (Security Account Manager) account names when integrated with Microsoft Active Directory, allowing MFA to be configured independently for each login method and potentially enabling attackers to bypass MFA by exploiting the alternative account name.
CVSS: CRITICAL (9.1) EPSS Score: 0.04%
January 10th, 2025 (6 months ago)
|
CVE-2024-12736 |
Description: The BU Section Editing WordPress plugin through 0.9.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CVSS: MEDIUM (6.1) EPSS Score: 0.04%
January 10th, 2025 (6 months ago)
|
CVE-2024-12731 |
Description: The Aklamator INfeed WordPress plugin through 2.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CVSS: MEDIUM (6.1) EPSS Score: 0.04%
January 10th, 2025 (6 months ago)
|
CVE-2024-12717 |
Description: The Aklamator INfeed WordPress plugin through 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVSS: MEDIUM (4.8) EPSS Score: 0.04%
January 10th, 2025 (6 months ago)
|
CVE-2024-12715 |
Description: The Asgard Security Scanner WordPress plugin through 0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CVSS: MEDIUM (6.1) EPSS Score: 0.04%
January 10th, 2025 (6 months ago)
|
CVE-2024-12714 |
Description: The Backlink Monitoring Manager WordPress plugin through 0.1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
EPSS Score: 0.04%
January 10th, 2025 (6 months ago)
|