In WordPress versions before 6.0.2 a medium severity vulnerability CVE-2024-4973 was detected. This vulnerability allows attackers to insert malicious code into posts or pages, which runs when someone views them, potentially compromising the site’s security. To fix this issue, users should upgrade WordPress to version 6.0.2. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-4973.
Read more CMSIn WordPress versions up to and including 2.0.6 a high severity vulnerability CVE-2024-4443 was detected. This vulnerability allows attackers to create malicious files on the site, potentially giving them control over the website. To fix this issue, users should upgrade WordPress to version 6.0.2. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-4443.
Read more CMSIn WordPress versions 1.8.0 and prior a high severity vulnerability CVE-2024-47304 was found. SQL Injection allows attackers to access sensitive data without authorization, posing a serious risk to confidentiality. Although the potential for data alteration or service disruption is low, the exposure of information could still compromise the security of the system. To fix this issue, users are advised to upgrade to version 1.8.1 or higher. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-47304.
Read more CMSIn Python versions prior to 0.22.4 a medium severity vulnerability CVE-2024-9979 was found. This vulnerability can cause crashes or data errors by accessing freed memory incorrectly. To fix this issue, users are advised to upgrade to version 0.22.4 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-9979.
Read more Application DevelopmentIn Grafana version 11.0.0 and prior a critical severity vulnerability CVE-2024-9264 was detected. The SQL Expressions feature in Grafana allows poorly sanitized duckdb queries with user input, leading to command injection and local file inclusion. Users with VIEWER or higher permissions can exploit this if the duckdb binary is in Grafana’s $PATH. To fix this issue, users need to update to versions 11.0.5, 11.1.6, 11.2.1, 11.0.6, 11.1.7, or 11.2.2. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-9264.
In Rancher versions 2.7.0 and prior, 2.8.0 and prior a medium severity vulnerability CVE-2024-21218 was detected. This vulnerability allows RKE1 clusters to repeatedly reconcile when secret encryption is enabled, exposing Kube API secret values in plaintext on the AppliedSpec. Cluster owners, members, and project members can access this data through the apiserver. To fix this issue, users are advised to upgrade to versions 2.7.14 and 2.8.5. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-22032.
Read more Developer ToolsIn Rancher versions >=2.7.0, < 2.7.14, >=2.8.0, <2.8.5 a high severity vulnerability CVE-2023-22650 was detected. This vulnerability allows deleted, disabled, or revoked users from an authentication provider to retain access in Rancher, leaving their tokens still usable. To fix this problem, users should upgrade to the latest version 2.7.14 and 2.8.5. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2023-22650.
Read more Data AnalyticsIn MariaDB version 11.1 a medium severity vulnerability CVE-2024-27766 was detected. This vulnerability allows remote attackers to execute arbitrary code through the lib_mysqludf_sys.so function. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-27766.
In MariaDB versions 10.5 a medium severity vulnerability CVE-2023-39593 was detected. This vulnerability allows authenticated attackers to execute arbitrary commands with elevated privileges. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39593.
Read more Database