Critical - CVE-2024-8584 - Orca HCM from LEARNING DIGITAL does not...
Orca HCM from LEARNING DIGITAL does not properly restrict access to a specific functionality, allowing unauthenticated remote attacker to exploit this functionality to create an account with...
Medium - CVE-2024-8585 - Orca HCM from LEARNING DIGITA does not properly...
Orca HCM from LEARNING DIGITA does not properly restrict a specific parameter of the file download functionality, allowing a remote attacker with regular privileges to download arbitrary system files.
Medium - CVE-2024-8586 - WebITR from Uniong has an Open Redirect...
WebITR from Uniong has an Open Redirect vulnerability, which allows unauthorized remote attackers to exploit this vulnerability to forge URLs. Users, believing they are accessing a trusted domain,...
NA - CVE-2024-45625 - Cross-site scripting vulnerability exists in...
Cross-site scripting vulnerability exists in Forminator versions prior to 1.34.1. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who follows...
NA - CVE-2024-5561 - The Popup Maker WordPress plugin before 1.19.1...
The Popup Maker WordPress plugin before 1.19.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting...