Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-09-25 CVE-2024-9028 Cross-site Scripting vulnerability in Devfarm WP GPX Maps
The WP GPX Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sgpx' shortcode in all versions up to, and including, 1.7.08 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
devfarm CWE-79
5.4
2024-09-25 CVE-2024-9068 Cross-site Scripting vulnerability in Themexclub Oneelements
The OneElements – Best Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.3.7 due to insufficient input sanitization and output escaping.
network
low complexity
themexclub CWE-79
5.4
2024-09-25 CVE-2024-9069 Cross-site Scripting vulnerability in Graphicsly
The Graphicsly – The ultimate graphics plugin for WordPress website builder ( Gutenberg, Elementor, Beaver Builder, WPBakery ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping.
network
low complexity
graphicsly CWE-79
5.4
2024-09-25 CVE-2024-9073 Cross-site Scripting vulnerability in Gutengeek Free Gutenberg Blocks
The GutenGeek Free Gutenberg Blocks for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping.
network
low complexity
gutengeek CWE-79
5.4
2024-09-25 CVE-2021-38963 Improper Neutralization of Formula Elements in a CSV File vulnerability in IBM Aspera Console 3.4.0/3.4.1/3.4.2
IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a CSV injection vulnerability.
network
low complexity
ibm CWE-1236
8.0
2024-09-25 CVE-2022-43845 Incorrect Permission Assignment for Critical Resource vulnerability in IBM Aspera Console 3.4.0/3.4.1/3.4.2
IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag.
network
low complexity
ibm CWE-732
7.5
2024-09-25 CVE-2023-5359 Cleartext Storage of Sensitive Information vulnerability in Boldgrid W3 Total Cache
The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.5 via Google OAuth API secrets stored in plaintext in the publicly visible plugin source.
network
low complexity
boldgrid CWE-312
7.5
2024-09-25 CVE-2024-38324 Improper Certificate Validation vulnerability in IBM Storage Defender 2.0.0/2.0.4
IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI does not validate server name during registration and unregistration operations which could expose sensitive information to an attacker with access to the system.
network
low complexity
ibm CWE-295
6.5
2024-09-25 CVE-2024-41725 Cross-site Scripting vulnerability in Doverfuelingsolutions products
ProGauge MAGLINK LX CONSOLE does not have sufficient filtering on input fields that are used to render pages which may allow cross site scripting.
network
low complexity
doverfuelingsolutions CWE-79
6.1
2024-09-25 CVE-2024-43423 Use of Hard-coded Credentials vulnerability in Doverfuelingsolutions products
The web application for ProGauge MAGLINK LX4 CONSOLE contains an administrative-level user account with a password that cannot be changed.
network
low complexity
doverfuelingsolutions CWE-798
critical
9.8