NA - CVE-2024-11841 - The Tithe.ly Giving Button WordPress plugin...
The Tithe.ly Giving Button WordPress plugin through 1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which...
NA - CVE-2024-56084 - An issue was discovered in Logpoint...
An issue was discovered in Logpoint UniversalNormalizer before 5.7.0. Authenticated users can inject payloads while creating Universal Normalizer. These are executed, leading to Remote Code Execution.
NA - CVE-2024-56085 - An issue was discovered in Logpoint before...
An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while creating Search Template Dashboard. These are executed, leading to Server-Side Template Injection.
NA - CVE-2024-56086 - An issue was discovered in Logpoint before...
An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads in Report Templates. These are executed when the backup process is initiated, leading to Remote Code...
NA - CVE-2024-56087 - An issue was discovered in Logpoint before...
An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while querying Search Template Dashboard. These are executed, leading to Server-Side Template Injection.
NA - CVE-2024-5333 - The Events Calendar WordPress plugin before...
The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events.
Critical - CVE-2024-12641 - TenderDocTransfer from Chunghwa Telecom has a...
TenderDocTransfer from Chunghwa Telecom has a Reflected Cross-site scripting vulnerability. The application sets up a simple local web server and provides APIs for communication with the target...
High - CVE-2024-12642 - TenderDocTransfer from Chunghwa Telecom has an...
TenderDocTransfer from Chunghwa Telecom has an Arbitrary File Write vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due...
High - CVE-2024-12643 - The tbm-client from Chunghwa Telecom has an...
The tbm-client from Chunghwa Telecom has an Arbitrary File Delete vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due...