NA - CVE-2024-8650 - An issue was discovered in GitLab CE/EE...
An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2 that allowed non-member users to view unresolved threads...
NA - CVE-2024-11841 - The Tithe.ly Giving Button WordPress plugin...
The Tithe.ly Giving Button WordPress plugin through 1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which...
NA - CVE-2024-56084 - An issue was discovered in Logpoint...
An issue was discovered in Logpoint UniversalNormalizer before 5.7.0. Authenticated users can inject payloads while creating Universal Normalizer. These are executed, leading to Remote Code Execution.
NA - CVE-2024-56085 - An issue was discovered in Logpoint before...
An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while creating Search Template Dashboard. These are executed, leading to Server-Side Template Injection.
NA - CVE-2024-56086 - An issue was discovered in Logpoint before...
An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads in Report Templates. These are executed when the backup process is initiated, leading to Remote Code...
NA - CVE-2024-56087 - An issue was discovered in Logpoint before...
An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while querying Search Template Dashboard. These are executed, leading to Server-Side Template Injection.
NA - CVE-2024-5333 - The Events Calendar WordPress plugin before...
The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events.
Critical - CVE-2024-12641 - TenderDocTransfer from Chunghwa Telecom has a...
TenderDocTransfer from Chunghwa Telecom has a Reflected Cross-site scripting vulnerability. The application sets up a simple local web server and provides APIs for communication with the target...
High - CVE-2024-12642 - TenderDocTransfer from Chunghwa Telecom has an...
TenderDocTransfer from Chunghwa Telecom has an Arbitrary File Write vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due...