A vulnerability has been found in Smart Post Show Plugin up to 3.0.0 on WordPress and classified as problematic. This vulnerability affects unknown code of the component Pagination Color Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-8187. The attack can be initiated remotely. There is no exploit available.
A vulnerability, which was classified as problematic, was found in Auto iFrame Plugin up to 1.7 on WordPress. This affects an unknown part. The manipulation of the argument tag leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-9449. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability, which was classified as problematic, has been found in Embed PDF Viewer Plugin up to 2.4.4 on WordPress. Affected by this issue is some unknown functionality. The manipulation of the argument height/width leads to cross site scripting.
This vulnerability is handled as CVE-2024-9451. The attack may be launched remotely. There is no exploit available.
A vulnerability classified as critical was found in Buildah. Affected by this vulnerability is an unknown functionality of the component Cache Mount Handler. The manipulation leads to path traversal.
This vulnerability is known as CVE-2024-9675. The attack needs to be done within the local network. There is no exploit available.
A vulnerability classified as problematic has been found in Foreman up to 3.2. Affected is an unknown function of the component GraphQL API. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2024-6861. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Red Hat 3Scale. It has been rated as critical. This issue affects some unknown processing of the component PDF Invoice Handler. The manipulation leads to missing authentication.
The identification of this vulnerability is CVE-2024-9671. The attack can only be done within the local network. There is no exploit available.
A vulnerability was found in Apache RocketMQ up to 4.9.5/5.1.0. It has been declared as critical. This vulnerability affects unknown code of the component NameServer/Broker/Controller. The manipulation leads to code injection.
This vulnerability was named CVE-2023-33426. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Adobe Substance 3D Stager. It has been classified as critical. This affects an unknown part of the component SKP File Parser. The manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2024-45138. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Adobe Dimension and classified as critical. Affected by this issue is some unknown functionality of the component SKP File Parser. The manipulation leads to use after free.
This vulnerability is handled as CVE-2024-45146. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in PHP up to 8.1.29/8.2.23/8.3.11 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Multipart Form Data Parser. The manipulation leads to improper validation of syntactic correctness of input.
This vulnerability is known as CVE-2024-8928. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, was found in i2p up to 2.2.x. Affected is an unknown function of the component Hidden Service Handler. The manipulation leads to observable behavioral discrepancy.
This vulnerability is traded as CVE-2023-36325. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in 3DSecure 2.0. This issue affects some unknown processing of the file threeDsMethod.jsp. The manipulation of the argument threeDSMethodData leads to cross site scripting.
The identification of this vulnerability is CVE-2024-25284. The attack may be initiated remotely. There is no exploit available.
A vulnerability classified as critical was found in HDF5 up to 1.14.3. This vulnerability affects the function H5A__close. The manipulation leads to memory corruption.
This vulnerability was named CVE-2024-32608. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic has been found in 3DSecure 2.0. This affects an unknown part of the component HTTP Header Handler. The manipulation of the argument Referer leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2024-25286. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in 3DSecure 2.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /rest/online. The manipulation of the argument params leads to cross site scripting.
This vulnerability is handled as CVE-2024-25283. The attack may be launched remotely. There is no exploit available.
A vulnerability was found in LemonLDAP::NG up to 2.19.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component OAuth2 Client Authentication. The manipulation of the argument client_password leads to improper authentication.
This vulnerability is known as CVE-2024-45160. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in za-internet C-MOR Video Surveillance 5.2401/6.00PL01. It has been classified as critical. Affected is an unknown function of the file settimezone.pml of the component Web Interface. The manipulation of the argument city leads to os command injection.
This vulnerability is traded as CVE-2024-45179. It is possible to launch the attack remotely. There is no exploit available.