Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-09-24 CVE-2024-8544 Cross-site Scripting vulnerability in Fatcatapps Pixel CAT
The Pixel Cat – Conversion Pixel Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.0.5.
network
low complexity
fatcatapps CWE-79
6.1
2024-09-24 CVE-2024-8657 Cross-site Scripting vulnerability in Ggnome Garden Gnome Package
The Garden Gnome Package plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ggpkg shortcode in all versions up to, and including, 2.2.9 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
ggnome CWE-79
5.4
2024-09-24 CVE-2024-8662 Cross-site Scripting vulnerability in Ibericode Koko Analytics
The Koko Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.3.12.
network
low complexity
ibericode CWE-79
6.1
2024-09-24 CVE-2024-8716 Cross-site Scripting vulnerability in Xplodedthemes XT Ajax ADD to Cart for Woocommerce
The XT Ajax Add To Cart for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.1.2.
network
low complexity
xplodedthemes CWE-79
6.1
2024-09-24 CVE-2024-8738 Cross-site Scripting vulnerability in Castos Seriously Simple Stats
The Seriously Simple Stats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.6.0.
network
low complexity
castos CWE-79
6.1
2024-09-24 CVE-2024-8795 Cross-Site Request Forgery (CSRF) vulnerability in Ba-Booking BA Book Everything
The BA Book Everything plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.20.
network
low complexity
ba-booking CWE-352
8.8
2024-09-23 CVE-2018-20072 Unspecified vulnerability in Google Chrome
Insufficient data validation in PDF in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform out of bounds memory access via a crafted PDF file.
local
low complexity
google
7.8
2024-09-23 CVE-2024-42861 Unspecified vulnerability in Linuxptp Project Linuxptp
An issue in IEEE 802.1AS linuxptp v.4.2 and before allowing a remote attacker to cause a denial of service via a crafted Pdelay_Req message to the time synchronization function
network
low complexity
linuxptp-project
7.5
2024-09-23 CVE-2024-8263 Unspecified vulnerability in Github Enterprise Server
An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use of nested tags.
network
low complexity
github
2.7
2024-09-23 CVE-2024-8770 Cross-site Scripting vulnerability in Github Enterprise Server
A Cross-Site Scripting (XSS) vulnerability was identified in the repository transfer feature of GitHub Enterprise Server, which allows attackers to steal sensitive user information via social engineering. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in version 3.10.17, 3.11.15, 3.12.9, 3.13.4, and 3.14.1. This vulnerability was reported via the GitHub Bug Bounty program.
network
low complexity
github CWE-79
6.1