Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-12-12 CVE-2024-12482 Path Traversal vulnerability in Cjbi Wetech-Cms 1.0/1.1/1.2
A vulnerability was found in cjbi wetech-cms 1.0/1.1/1.2.
network
low complexity
cjbi CWE-22
4.3
2024-12-12 CVE-2024-12483 Authorization Bypass Through User-Controlled Key vulnerability in Ujcms
A vulnerability classified as problematic has been found in Dromara UJCMS up to 9.6.3.
network
high complexity
ujcms CWE-639
5.9
2024-12-11 CVE-2024-11351 The Restrict – membership, site, content and user access restrictions for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.8 via the WordPress core search feature.
network
low complexity
CWE-200
5.3
2024-12-11 CVE-2024-51460 IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information when a detailed technical error message is returned in a stack trace.
network
low complexity
CWE-209
4.3
2024-12-11 CVE-2024-12325 The Waymark plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, 1.4.1 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
6.1
2024-12-11 CVE-2024-11008 The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.10 via the WordPress core search feature.
network
low complexity
CWE-200
5.3
2024-12-11 CVE-2024-12294 The Last Viewed Posts by WPBeginner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.1 via the 'get_legacy_cookies' function.
network
low complexity
CWE-284
5.3
2024-12-11 CVE-2024-12004 The WPC Order Notes for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.2.
network
low complexity
CWE-352
6.1
2024-12-11 CVE-2024-12283 The WP Pipes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘x1’ parameter in all versions up to, and including, 1.4.1 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
6.1
2024-12-11 CVE-2024-35117 IBM OpenPages with Watson 9.0 may write sensitive information, under specific configurations, in clear text to the system tracing log files that could be obtained by a privileged user.
network
high complexity
CWE-312
4.4