A vulnerability was found in WPAdverts Plugin up to 2.1.7 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-10890. The attack may be launched remotely. There is no exploit available.
A vulnerability has been found in 7-Zip and classified as critical. Affected by this vulnerability is an unknown functionality of the component Zstandard Decompression Handler. The manipulation leads to integer underflow.
This vulnerability is known as CVE-2024-11477. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, was found in Kubernetes up to 1.28.11/1.29.6/1.30.2. Affected is an unknown function of the component gitRepo Volume Handler. The manipulation leads to Privilege Escalation.
This vulnerability is traded as CVE-2024-10220. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in Brocade SANnav up to 2.2.1. This issue affects some unknown processing. The manipulation leads to risky cryptographic algorithm.
The identification of this vulnerability is CVE-2022-43934. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic was found in Brocade SANnav up to 2.2.1. This vulnerability affects unknown code. The manipulation leads to sensitive information in log files.
This vulnerability was named CVE-2022-43935. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic has been found in pickplugins Product Designer Plugin up to 1.0.35 on WordPress. This affects an unknown part of the component SVG File Upload Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-9111. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in Brocade SANnav up to 2.2.1. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to file and directory information exposure.
This vulnerability is handled as CVE-2022-43933. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in wolfgang101 Include Mastodon Feed Plugin up to 1.9.5 on WordPress. It has been classified as problematic. Affected is the function include-mastodon-feed of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-11455. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability was found in faktorvier F4 Improvements Plugin up to 1.9.0 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component SVG File Upload Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-9442. The attack can be launched remotely. There is no exploit available.
A vulnerability was found in peepso Community Plugin up to 6.4.6.2 on WordPress and classified as problematic. This issue affects some unknown processing. The manipulation of the argument filter leads to cross site scripting.
The identification of this vulnerability is CVE-2024-11447. The attack may be initiated remotely. There is no exploit available.
A vulnerability has been found in aishan Lazy load videos and sticky control Plugin up to 3.0.0 on WordPress and classified as problematic. This vulnerability affects the function lazy-load-videos-and-sticky-control of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-11428. The attack can be initiated remotely. There is no exploit available.
A vulnerability, which was classified as problematic, has been found in goback2 salavat counter Plugin up to 0.9.1 on WordPress. Affected by this issue is some unknown functionality. The manipulation of the argument page leads to cross site scripting.
This vulnerability is handled as CVE-2024-11435. The attack may be launched remotely. There is no exploit available.
A vulnerability, which was classified as problematic, was found in feedmymedia LSX Tour Operator Plugin up to 1.4.9 on WordPress. This affects an unknown part of the component SVG File Upload Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-9851. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability classified as problematic was found in greyowl0015 Grey Owl Lightbox Plugin up to 1.6.1 on WordPress. Affected by this vulnerability is the function gol_button of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-11440. The attack can be launched remotely. There is no exploit available.
A vulnerability classified as problematic has been found in pengbos Slick Sitemap Plugin up to 2.0.0 on WordPress. Affected is the function slick-sitemap of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-11424. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability was found in alexvtn WIP Incoming Lite Plugin up to 1.1.1 on WordPress. It has been rated as problematic. This issue affects the function save_option of the component Setting Handler. The manipulation leads to cross-site request forgery.
The identification of this vulnerability is CVE-2024-11416. The attack may be initiated remotely. There is no exploit available.
A vulnerability was found in alexvtn SuevaFree Essential Kit Plugin up to 1.1.3 on WordPress. It has been declared as problematic. This vulnerability affects the function counter of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-11432. The attack can be initiated remotely. There is no exploit available.
A vulnerability was found in Opencast up to 13.9/14.2. It has been classified as critical. This affects an unknown part of the component Video Capture Handler. The manipulation leads to allocation of resources.
This vulnerability is uniquely identified as CVE-2024-52797. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
Threat hunters are warning about an updated version of the Python-based NodeStealer that's now equipped to extract more information from victims' Facebook Ads Manager accounts and harvest credit card data stored in web browsers.
"They collect budget details of Facebook Ads Manager accounts of their victims, which might be a gateway for Facebook malvertisement," Netskope Threat Labs researcher