Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-09-18 CVE-2024-6641 Incorrect Comparison vulnerability in Getastra WP Hardening
The WP Hardening – Fix Your WordPress Security plugin for WordPress is vulnerable to Security Feature Bypass in all versions up to, and including, 1.2.6.
network
low complexity
getastra CWE-697
5.3
2024-09-18 CVE-2022-39068 Out-of-bounds Write vulnerability in ZTE Mf296R Firmware Mf296Rnordic1B06
There is a buffer overflow vulnerability in ZTE MF296R.
network
low complexity
zte CWE-787
6.5
2024-09-18 CVE-2024-43970 Cross-site Scripting vulnerability in Surecart
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SureCart allows Reflected XSS.This issue affects SureCart: from n/a through 2.29.3.
network
low complexity
surecart CWE-79
6.1
2024-09-18 CVE-2024-43971 Cross-site Scripting vulnerability in Sunshinephotocart Sunshine Photo Cart
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Sunshine Sunshine Photo Cart allows Reflected XSS.This issue affects Sunshine Photo Cart: from n/a through 3.2.5.
network
low complexity
sunshinephotocart CWE-79
6.1
2024-09-18 CVE-2024-43972 Cross-site Scripting vulnerability in Pagelayer
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pagelayer Team PageLayer allows Stored XSS.This issue affects PageLayer: from n/a through 1.8.7.
network
low complexity
pagelayer CWE-79
4.8
2024-09-18 CVE-2024-43975 Cross-site Scripting vulnerability in Superstorefinder Super Store Finder
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in highwarden Super Store Finder allows Cross-Site Scripting (XSS).This issue affects Super Store Finder: from n/a through 6.9.7.
network
low complexity
superstorefinder CWE-79
6.1
2024-09-18 CVE-2024-43983 Cross-site Scripting vulnerability in Podlove Podcast Publisher
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Podlove Podlove Podcast Publisher allows Stored XSS.This issue affects Podlove Podcast Publisher: from n/a through 4.1.13.
network
low complexity
podlove CWE-79
5.4
2024-09-18 CVE-2024-43987 Cross-site Scripting vulnerability in Wayneconnor Sliding Door
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in wayneconnor Sliding Door allows Stored XSS.This issue affects Sliding Door: from n/a through 3.6.
network
low complexity
wayneconnor CWE-79
5.4
2024-09-18 CVE-2024-43988 Cross-site Scripting vulnerability in Digitalnature Mystique
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in digitalnature Mystique allows Stored XSS.This issue affects Mystique: from n/a through 2.5.7.
network
low complexity
digitalnature CWE-79
5.4
2024-09-18 CVE-2024-43991 Cross-site Scripting vulnerability in Webdzier Hotel Galaxy
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in webdzier Hotel Galaxy allows Stored XSS.This issue affects Hotel Galaxy: from n/a through 4.4.24.
network
low complexity
webdzier CWE-79
5.4