Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-09-18 CVE-2024-44005 Cross-site Scripting vulnerability in Greenshiftwp Greenshift - Animation and Page Builder Blocks
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wpsoul Greenshift – animation and page builder blocks allows Stored XSS.This issue affects Greenshift – animation and page builder blocks: from n/a through 9.3.7.
network
low complexity
greenshiftwp CWE-79
5.4
2024-09-17 CVE-2024-37985 Unspecified vulnerability in Microsoft Windows 11 22H2 and Windows 11 23H2
Windows Kernel Information Disclosure Vulnerability
local
high complexity
microsoft
5.6
2024-09-17 CVE-2024-43976 SQL Injection vulnerability in Superstorefinder Super Store Finder
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super Store Finder allows SQL Injection.This issue affects Super Store Finder: from n/a through 6.9.7.
network
low complexity
superstorefinder CWE-89
critical
9.8
2024-09-17 CVE-2024-43977 Cross-site Scripting vulnerability in Posimyth the Plus Addons for Elementor
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite allows Stored XSS.This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through 5.6.2.
network
low complexity
posimyth CWE-79
5.4
2024-09-17 CVE-2024-43978 SQL Injection vulnerability in Superstorefinder Super Store Finder
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super Store Finder allows SQL Injection.This issue affects Super Store Finder: from n/a before 6.9.8.
network
low complexity
superstorefinder CWE-89
critical
9.8
2024-09-17 CVE-2024-43985 Cross-site Scripting vulnerability in Mage-People BUS Ticket Booking With Seat Reservation
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MagePeople Team Bus Ticket Booking with Seat Reservation allows Stored XSS.This issue affects Bus Ticket Booking with Seat Reservation: from n/a through 5.3.5.
network
low complexity
mage-people CWE-79
4.8
2024-09-17 CVE-2024-44004 SQL Injection vulnerability in Wptaskforce Track & Trace
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPTaskForce WPCargo Track & Trace allows SQL Injection.This issue affects WPCargo Track & Trace: from n/a through 7.0.6.
network
low complexity
wptaskforce CWE-89
critical
9.8
2024-09-17 CVE-2024-44007 Cross-site Scripting vulnerability in Sktthemes SKT Templates
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SKT Themes SKT Templates – Elementor & Gutenberg templates allows Reflected XSS.This issue affects SKT Templates – Elementor & Gutenberg templates: from n/a through 6.14.
network
low complexity
sktthemes CWE-79
6.1
2024-09-17 CVE-2024-44008 Cross-site Scripting vulnerability in Cyberhobo GEO Mashup
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dylan Kuhn Geo Mashup allows Stored XSS.This issue affects Geo Mashup: from n/a through 1.13.12.
network
low complexity
cyberhobo CWE-79
5.4
2024-09-17 CVE-2024-44009 Cross-site Scripting vulnerability in Wclovers Wcfm Marketplace
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WC Lovers WCFM Marketplace allows Reflected XSS.This issue affects WCFM Marketplace: from n/a through 3.6.10.
network
low complexity
wclovers CWE-79
6.1