Medium - CVE-2024-12395 - The WooCommerce Additional Fees On Checkout...
The WooCommerce Additional Fees On Checkout (Free) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘number’ parameter in all versions up to, and including, 1.4.7 due to...
Medium - CVE-2024-12601 - The Calculated Fields Form plugin for WordPress...
The Calculated Fields Form plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 5.2.63. This is due to unlimited height and width parameters for CAPTCHA...
NA - CVE-2024-52542 - Dell AppSync, version 4.6.0.x, contain a...
Dell AppSync, version 4.6.0.x, contain a Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to...
Medium - CVE-2024-8429 - Improper Restriction of Excessive...
Improper Restriction of Excessive Authentication Attempts vulnerability in Digital Operation Services WiFiBurada allows Use of Known Domain Credentials.This issue affects WiFiBurada: before 1.0.5.
Medium - CVE-2024-8475 - Authentication Bypass by Assumed-Immutable Data...
Authentication Bypass by Assumed-Immutable Data vulnerability in Digital Operation Services WiFiBurada allows Manipulating User-Controlled Variables.This issue affects WiFiBurada: before 1.0.5.
Low - CVE-2024-9654 - The Easy Digital Downloads plugin for WordPress...
The Easy Digital Downloads plugin for WordPress is vulnerable to Improper Authorization in versions 3.1 through 3.3.4. This is due to a lack of sufficient validation checks within the...
Medium - CVE-2024-10356 - The ElementsReady Addons for Elementor plugin...
The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.4.8 in inc/Widgets/accordion/output/content.php....
NA - CVE-2024-50379 - Time-of-check Time-of-use (TOCTOU) Race...
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write...
NA - CVE-2024-54677 - Uncontrolled Resource Consumption vulnerability...
Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service. This issue affects Apache Tomcat: from 11.0.0-M1 through...
Medium - CVE-2024-9819 - Authorization Bypass Through User-Controlled...
Authorization Bypass Through User-Controlled Key vulnerability in NextGeography NG Analyser allows Functionality Misuse.This issue affects NG Analyser: before 2.2.711.