Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In October 2024
The Discount Rules for WooCommerce – Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.6.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a site administrator into performing an action such as clicking on a link. Please note that this is only exploitable when the 'Leave a Review' notice is present, which occurs after 100 orders are made and disappears after a user dismisses the notice.
CVSS Score
4.7
EPSS Score
0.012
Published
2024-10-16
The Smart Online Order for Clover plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.5.7. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
CVSS Score
6.1
EPSS Score
0.009
Published
2024-10-16
IBM Watson Studio Local 1.2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
CVSS Score
4.3
EPSS Score
0.001
Published
2024-10-16
Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.
CVSS Score
8.7
EPSS Score
0.013
Published
2024-10-15
Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a network attack vector.
CVSS Score
8.6
EPSS Score
0.014
Published
2024-10-15
Improper access control in Imagine Cup allows an authorized attacker to elevate privileges over a network.
CVSS Score
7.5
EPSS Score
0.066
Published
2024-10-15
Opening an external link to an HTTP website when Firefox iOS was previously closed and had an HTTPS tab open could in some cases result in the padlock icon showing an HTTPS indicator incorrectly This vulnerability affects Firefox for iOS < 131.2.
CVSS Score
9.1
EPSS Score
0.004
Published
2024-10-15
IBM WebSphere Application Server 8.5 is vulnerable to a denial of service, under certain configurations, caused by an unexpected specially crafted request. A remote attacker could exploit this vulnerability to cause an error resulting in a denial of service.
CVSS Score
5.9
EPSS Score
0.002
Published
2024-10-15
Use after free in AI in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVSS Score
8.8
EPSS Score
0.044
Published
2024-10-15
Use after free in WebAuthentication in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVSS Score
8.8
EPSS Score
0.204
Published
2024-10-15


Contact Us

Shodan ® - All rights reserved