Low - CVE-2022-43845 - IBM Aspera Console 3.4.0 through 3.4.4 could...
IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this...
NA - CVE-2023-26686 - File Upload vulnerability in CS-Cart...
File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the image upload feature when customizing a shop.
NA - CVE-2023-26687 - Directory Traversal vulnerability in CS-Cart...
Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to obtain sensitive information via the product_data parameter in the PDF Add-on.
NA - CVE-2023-26688 - Cross Site Scripting (XSS) vulnerability in...
Cross Site Scripting (XSS) vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the product_data parameter of add/edit product in the administration interface.
NA - CVE-2023-26690 - File Upload vulnerability in CS-Cart...
File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via File Manager/Editor component in the vendor or admin menu.
NA - CVE-2023-26691 - Directory Traversal vulnerability in CS-Cart...
Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via crafted zip file when installing a new add-on.
Low - CVE-2023-5359 - The W3 Total Cache plugin for WordPress is...
The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.5 via Google OAuth API secrets stored in plaintext in the publicly...
NA - CVE-2024-21545 - Proxmox Virtual Environment is an open-source...
Proxmox Virtual Environment is an open-source server management platform for enterprise virtualization. Insufficient safeguards against malicious API response values allow authenticated attackers...
Medium - CVE-2024-38324 - IBM Storage Defender 2.0.0 through 2.0.7...
IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI does not validate server name during registration and unregistration operations which could expose sensitive information to...