NA - CVE-2023-42133 - PAX Android based POS devices allow for...
PAX Android based POS devices allow for escalation of privilege via improperly configured scripts. An attacker must have shell access with system account privileges in order to exploit this...
NA - CVE-2024-21534 - Versions of the package jsonpath-plus before...
Versions of the package jsonpath-plus before 10.0.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by...
NA - CVE-2024-45315 - The Improper link resolution before file access...
The Improper link resolution before file access ('Link Following') vulnerability in SonicWall Connect Tunnel (version 12.4.3.271 and earlier of Windows client) allows users with standard...
NA - CVE-2024-45316 - The Improper link resolution before file access...
The Improper link resolution before file access ('Link Following') vulnerability in SonicWall Connect Tunnel (version 12.4.3.271 and earlier of Windows client) allows users with standard...
NA - CVE-2024-45317 - A Server-Side Request Forgery (SSRF)...
A Server-Side Request Forgery (SSRF) vulnerability in SMA1000 appliance firmware versions 12.4.3-02676 and earlier allows a remote, unauthenticated attacker to cause the SMA1000 server-side...
NA - CVE-2024-48987 - Snipe-IT before 7.0.10 allows remote code...
Snipe-IT before 7.0.10 allows remote code execution (associated with cookie serialization) when an attacker knows the APP_KEY. This is exacerbated by .env files, available from the product's...
NA - CVE-2024-5005 - An issue has been discovered discovered in...
An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 11.4 before 17.2.9, all versions starting from 17.3 before 17.3.5, all versions starting from 17.4...
NA - CVE-2024-6971 - A path traversal vulnerability exists in the...
A path traversal vulnerability exists in the parisneo/lollms-webui repository, specifically in the `lollms_file_system.py` file. The functions `add_rag_database`, `toggle_mount_rag_database`, and...
Medium - CVE-2024-7514 - The WordPress Comments Import & Export plugin...
The WordPress Comments Import & Export plugin for WordPress is vulnerable to to arbitrary file read due to insufficient file path validation during the comments import process, in versions up to,...
Medium - CVE-2024-8913 - The The Plus Addons for Elementor – Elementor...
The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and...