NA - CVE-2024-10892 - The Cost Calculator Builder WordPress plugin...
The Cost Calculator Builder WordPress plugin before 3.2.43 does not have CSRF checks in some AJAX actions, which could allow attackers to make logged in users perform unwanted actions via CSRF...
Versions of the package unisharp/laravel-filemanager before 2.9.1 are vulnerable to Remote Code Execution (RCE) through using a valid mimetype and inserting the . character after the php file...
NA - CVE-2024-21547 - Versions of the package spatie/browsershot...
Versions of the package spatie/browsershot before 5.0.2 are vulnerable to Directory Traversal due to URI normalisation in the browser where the file:// check can be bypassed with file:\\. An...
NA - CVE-2024-21548 - Versions of the package bun before 1.1.30 are...
Versions of the package bun before 1.1.30 are vulnerable to Prototype Pollution due to improper input sanitization. An attacker can exploit this vulnerability through Bun's APIs that accept...
NA - CVE-2024-4464 - Authorization bypass through user-controlled...
Authorization bypass through user-controlled key vulnerability in streaming service in Synology Media Server before 1.4-2680, 2.0.5-3152 and 2.2.0-3325 allows remote attackers to read specific...
NA - CVE-2024-56173 - In Optimizely Configured Commerce before...
In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under specific conditions: XSS from JavaScript in an SVG document.
NA - CVE-2024-56174 - In Optimizely Configured Commerce before...
In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under specific conditions: XSS from client-side template...
NA - CVE-2024-56175 - In Optimizely Configured Commerce before...
In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under specific conditions: XSS from client-side template...
Medium - CVE-2024-11295 - The Simple Page Access Restriction plugin for...
The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.29 via the WordPress core search feature. This...
Critical - CVE-2024-12287 - The Biagiotti Membership plugin for WordPress...
The Biagiotti Membership plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.0.2. This is due to the plugin not properly verifying a user's...