2024-12-11 | CVE-2024-12294 | The Last Viewed Posts by WPBeginner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.1 via the 'get_legacy_cookies' function. | 5.3 |
2024-12-11 | CVE-2024-12004 | The WPC Order Notes for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.2. | 6.1 |
2024-12-11 | CVE-2024-12283 | The WP Pipes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘x1’ parameter in all versions up to, and including, 1.4.1 due to insufficient input sanitization and output escaping. | 6.1 |
2024-12-11 | CVE-2024-52537 | Link Following vulnerability in Dell products Dell Client Platform Firmware Update Utility contains an Improper Link Resolution vulnerability. | 6.7 |
2024-12-11 | CVE-2024-53289 | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Dell Thinos 2408 Dell ThinOS version 2408 contains a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. | 7.0 |
2024-12-11 | CVE-2024-53290 | Command Injection vulnerability in Dell Thinos 2408 Dell ThinOS version 2408 contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. | 8.4 |
2024-12-11 | CVE-2024-53292 | Insufficiently Protected Credentials vulnerability in Dell Vxrail Hyperconverged Infrastructure Dell VxVerify, versions prior to x.40.405, contain a Plain-text Password Storage Vulnerability in the shell wrapper. | 6.7 |
2024-12-11 | CVE-2023-37395 | Use of a Broken or Risky Cryptographic Algorithm vulnerability in IBM Aspera Faspex IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to improper encryption of certain data. | 3.3 |
2024-12-11 | CVE-2024-35117 | IBM OpenPages with Watson 9.0 may write sensitive information, under specific configurations, in clear text to the system tracing log files that could be obtained by a privileged user. | 4.4 |
2024-12-10 | CVE-2024-43712 | Cross-site Scripting vulnerability in Adobe Experience Manager Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could allow an attacker to execute arbitrary code in the context of the victim's browser. | 5.4 |