| CVE-2024-22029 | tomcat packaging allows for escalation to root from tomcat user | SUSE | Container suse/manager/5.0/x86_64/server:5.0.0-beta1.2.122 | High | 7.8 | 2024-10-16 13:20:48 | Deep Dive |
| CVE-2022-4974 | Freemius SDK <= 2.4.2 - Missing Authorization Checks | dashlabsltd | YASR – Yet Another Star Rating Plugin for WordPress | Medium | 6.3 | 2024-10-16 06:43:30 | Deep Dive |
| CVE-2024-9521 | SEO Manager <= 1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta | india-web-developer | SEO Manager | Medium | 6.4 | 2024-10-16 02:05:00 | Deep Dive |
| CVE-2024-47779 | Element Web vulnerable to potential exposure of access token via authenticated media | element-hq | element-web | 中危 | - | 2024-10-15 15:28:00 | Deep Dive |
| CVE-2024-8513 | QA Analytics <= 4.1.1.1 - Missing Authorization to Unauthenticated Settings Update | quarka | QA Assistants – Driven by data | Medium | 5.3 | 2024-10-10 02:06:05 | Deep Dive |
| CVE-2024-37179 | Insecure File Operations vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence) | SAP_SE | SAP BusinessObjects Business Intelligence Platform (Web Intelligence) | High | 7.7 | 2024-10-08 03:21:03 | Deep Dive |
| CVE-2024-47379 | WordPress Web Directory Free plugin <= 1.7.3 - Reflected Cross Site Scripting (XSS) vulnerability | Shamalli | Web Directory Free | High | 7.1 | 2024-10-05 15:01:32 | Deep Dive |
| CVE-2024-25694 | BUG-000163019 - Stored XSS in Portal for ArcGIS | Esri | Enterprise Web App Builder | Medium | 4.8 | 2024-10-04 17:17:59 | Deep Dive |
| CVE-2024-25702 | BUG-000160599 - Stored XSS in Portal for ArcGIS Web App Builder | Esri | ArcGIS Enterprise Web App Builder | Medium | 4.8 | 2024-10-04 17:17:13 | Deep Dive |
| CVE-2024-7824 | Type-confusion vulnerability that can cause the WRSA.exe service to crash and generate a crash dump | Webroot | SecureAnywhere - Web Shield | 中危 | - | 2024-10-03 17:05:38 | Deep Dive |
| CVE-2024-7825 | Type confusion that can cause the WRSA.exe service to crash and generate a crash dump | Webroot | SecureAnywhere - Web Shield | 中危 | - | 2024-10-03 17:05:36 | Deep Dive |
| CVE-2024-7826 | Unhandled exception vulnerability that can cause the WRSA.exe service to crash and generate a crash dump | Webroot | SecureAnywhere - Web Shield | 中危 | - | 2024-10-03 17:05:33 | Deep Dive |
| CVE-2024-8352 | Social Web Suite – Social Media Auto Post, Social Media Auto Publish <= 4.1.11 - Directory Traversal to Arbitrary File Download | dejanmarkovic | Social Web Suite – Social Media Auto Post, Social Media Auto Publish | High | 7.5 | 2024-10-03 03:32:01 | Deep Dive |
| CVE-2024-9344 | BerqWP – Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript <= 2.1.1 - Reflected Cross-Site Scripting | berqwp | BerqWP – Automated All-In-One Page Speed Optimization for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript | Medium | 6.1 | 2024-10-02 08:31:50 | Deep Dive |
| CVE-2024-8800 | RabbitLoader – Website Speed Optimization for improving Core Web Vital metrics with Cache, Image Optimization, and more <= 2.21.0 - Reflected Cross-Site Scripting | sanrl | RabbitLoader – AI Speed Optimization, Caching & CDN for WordPress & WooCommerce | Medium | 6.1 | 2024-10-02 07:35:30 | Deep Dive |
| CVE-2024-8967 | PWA — easy way to Progressive Web App <= 1.6.3 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload | iworks | PWA — easy way to Progressive Web App | Medium | 6.4 | 2024-10-02 07:35:26 | Deep Dive |
| CVE-2024-47295 | SEIKO EPSON Web Config 安全漏洞 | SEIKO EPSON CORPORATION | Web Config | 高危 | - | 2024-10-01 03:16:40 | Deep Dive |
| CVE-2024-28170 | Intel RAID Web Console 访问控制错误漏洞 | - | Intel(R) RAID Web Console | Low | 3.3 | 2024-09-16 16:38:40 | Deep Dive |
| CVE-2024-36261 | Intel RAID Web Console 访问控制错误漏洞 | - | Intel(R) RAID Web Console software | Low | 3.5 | 2024-09-16 16:38:40 | Deep Dive |
| CVE-2024-36247 | Intel Raid Web Console 访问控制错误漏洞 | - | Intel(R) RAID Web Console | Medium | 4.6 | 2024-09-16 16:38:39 | Deep Dive |