Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-08-15 CVE-2024-7063 The ElementsKit Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.6 via the 'render_raw' function.
network
low complexity
4.3
2024-08-15 CVE-2024-7064 The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 3.6.5 due to insufficient input sanitization and output escaping.
network
low complexity
6.4
2024-08-15 CVE-2024-6534 Authorization Bypass Through User-Controlled Key vulnerability in Monospace Directus 10.13.0
Directus v10.13.0 allows an authenticated external attacker to modify presets created by the same user to assign them to another user.
network
low complexity
monospace CWE-639
4.3
2024-08-15 CVE-2024-7814 Cross-site Scripting vulnerability in Online Railway Reservation System Project Online Railway Reservation System 1.0
A vulnerability, which was classified as problematic, was found in CodeAstro Online Railway Reservation System 1.0.
4.8
2024-08-15 CVE-2024-7815 Cross-site Scripting vulnerability in Online Railway Reservation System Project Online Railway Reservation System 1.0
A vulnerability has been found in CodeAstro Online Railway Reservation System 1.0 and classified as problematic.
4.8
2024-08-15 CVE-2024-25024 Cleartext Storage of Sensitive Information vulnerability in IBM Cloud PAK for Security and Qradar Suite
IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores user credentials in plain clear text which can be read by a local user.
local
low complexity
ibm CWE-312
5.5
2024-08-15 CVE-2024-6533 Cross-site Scripting vulnerability in Monospace Directus 10.13.0
Directus v10.13.0 allows an authenticated external attacker to execute arbitrary JavaScript on the client.
network
low complexity
monospace CWE-79
5.4
2024-08-15 CVE-2024-7420 Cross-Site Request Forgery (CSRF) vulnerability in Xyzscripts Insert PHP Code Snippet
The Insert PHP Code Snippet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.6.
network
low complexity
xyzscripts CWE-352
6.5
2024-08-15 CVE-2024-7812 Cross-site Scripting vulnerability in Mayurik Best House Rental Management System 1.0
A vulnerability classified as problematic was found in SourceCodester Best House Rental Management System 1.0.
network
low complexity
mayurik CWE-79
5.4
2024-08-15 CVE-2024-7809 Unspecified vulnerability in Tamparongj 03 Online Graduate Tracer System 1.0
A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0.
network
low complexity
tamparongj-03
5.3