NA - CVE-2024-56087 - An issue was discovered in Logpoint before...
An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while querying Search Template Dashboard. These are executed, leading to Server-Side Template Injection.
NA - CVE-2024-5333 - The Events Calendar WordPress plugin before...
The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events.
Critical - CVE-2024-12641 - TenderDocTransfer from Chunghwa Telecom has a...
TenderDocTransfer from Chunghwa Telecom has a Reflected Cross-site scripting vulnerability. The application sets up a simple local web server and provides APIs for communication with the target...
High - CVE-2024-12642 - TenderDocTransfer from Chunghwa Telecom has an...
TenderDocTransfer from Chunghwa Telecom has an Arbitrary File Write vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due...
High - CVE-2024-12643 - The tbm-client from Chunghwa Telecom has an...
The tbm-client from Chunghwa Telecom has an Arbitrary File Delete vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due...
High - CVE-2024-12644 - The tbm-client from Chunghwa Telecom has an...
The tbm-client from Chunghwa Telecom has an Arbitrary File vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the...
Medium - CVE-2024-12645 - The topm-client from Chunghwa Telecom has an...
The topm-client from Chunghwa Telecom has an Arbitrary File Read vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to...
High - CVE-2024-12646 - The topm-client from Chunghwa Telecom has an...
The topm-client from Chunghwa Telecom has an Arbitrary File Delete vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due...
NA - CVE-2024-9678 - An SQL Injection vulnerability existed in DLP...
An SQL Injection vulnerability existed in DLP Extension 11.11.1.3. The vulnerability allowed an attacker to perform arbitrary SQL queries potentially leading to command execution.