CVE-2024-35495
https://notcve.org/view.php?id=CVE-2024-35495
An Information Disclosure vulnerability in the Telemetry component in TP-Link Kasa KP125M V1.0.0 and Tapo P125M 1.0.0 Build 220930 Rel.143947 allows attackers to observe device state via observing network traffic. • https://github.com/Chapoly1305/tp-link-cve/blob/main/CVE-2024-35495.md • CWE-319: Cleartext Transmission of Sensitive Information •
CVE-2024-46635
https://notcve.org/view.php?id=CVE-2024-46635
An issue in the API endpoint /AccountMaster/GetCurrentUserInfo of INROAD before v202402060 allows attackers to access sensitive information via a crafted payload to the UserNameOrPhoneNumber parameter. • https://github.com/h1thub/CVE-2024-46635 https://hithub.notion.site/Sensitive-Information-Disclosure-in-GongZhiDao-System-aaad25d2430f4a638d462194cfa87c8b • CWE-922: Insecure Storage of Sensitive Information •
CVE-2024-9282 – bg5sbk MiniCMS page-edit.php cross-site request forgery
https://notcve.org/view.php?id=CVE-2024-9282
The initial researcher advisory mentions confusing version and file name information. The vendor was contacted early about this disclosure but did not respond in any way. • https://github.com/bg5sbk/MiniCMS/issues/52 https://vuldb.com/?ctiid.278664 https://vuldb.com/?id.278664 https://vuldb.com/?submit.411165 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2024-9281 – bg5sbk MiniCMS post-edit.php cross-site request forgery
https://notcve.org/view.php?id=CVE-2024-9281
The initial researcher advisory mentions confusing version and file name information. The vendor was contacted early about this disclosure but did not respond in any way. • https://github.com/bg5sbk/MiniCMS/issues/51 https://vuldb.com/?ctiid.278663 https://vuldb.com/?id.278663 https://vuldb.com/?submit.411164 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2024-47344 – WordPress uListing plugin <= 2.1.5 - Sensitive Data Exposure vulnerability
https://notcve.org/view.php?id=CVE-2024-47344
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StylemixThemes uListing.This issue affects uListing: from n/a through 2.1.5. The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.1.5 via the /pricing-plan/payment endpoint. • https://patchstack.com/database/vulnerability/ulisting/wordpress-ulisting-plugin-2-1-5-sensitive-data-exposure-vulnerability? • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •