Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-07-02 CVE-2024-34122 Acrobat for Edge versions 126.0.2592.68 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure.
local
low complexity
CWE-125
7.8
2024-07-02 CVE-2024-4268 The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in all versions up to, and including, 3.1.9 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
CWE-79
5.4
2024-07-02 CVE-2024-6088 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized user registration due to a missing capability check on the 'register' function in all versions up to, and including, 4.2.6.8.1.
network
low complexity
CWE-862
5.3
2024-07-02 CVE-2024-6099 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthenticated bypass to user registration in versions up to, and including, 4.2.6.8.1.
network
low complexity
5.3
2024-07-02 CVE-2024-6264 The Post Meta Data Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘$meta_key’ parameter in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
5.4
2024-07-02 CVE-2024-6438 SQL Injection vulnerability in Hitout Carsale 1.0
A vulnerability has been found in Hitout Carsale 1.0 and classified as critical.
network
low complexity
hitout CWE-89
6.5
2024-07-02 CVE-2024-6439 Unrestricted Upload of File with Dangerous Type vulnerability in Home Owners Collection Management System Project Home Owners Collection Management System 1.0
A vulnerability was found in SourceCodester Home Owners Collection Management System 1.0 and classified as critical.
9.8
2024-07-02 CVE-2024-6440 SQL Injection vulnerability in Home Owners Collection Management System Project Home Owners Collection Management System 1.0
A vulnerability was found in SourceCodester Home Owners Collection Management System 1.0.
9.8
2024-07-02 CVE-2024-34590 Unspecified vulnerability in Samsung Android 12.0/13.0/14.0
Improper input validation?in parsing an item type from RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service.
network
low complexity
samsung
4.3
2024-07-02 CVE-2024-34591 Unspecified vulnerability in Samsung Android 12.0/13.0/14.0
Improper input validation in parsing an item data from RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service.
network
low complexity
samsung
4.3