NA - CVE-2024-7143 - A flaw was found in the Pulp package. When a...
A flaw was found in the Pulp package. When a role-based access control (RBAC) object in Pulp is set to assign permissions on its creation, it uses the `AutoAddObjPermsMixin` (typically the...
NA - CVE-2024-7584 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, was found in Tenda i22 1.0.0.3(4687). Affected is the function formApPortalPhoneAuth of the file /goform/apPortalPhoneAuth. The manipulation of...
NA - CVE-2024-7585 - A vulnerability has been found in Tenda i22...
A vulnerability has been found in Tenda i22 1.0.0.3(4687) and classified as critical. Affected by this vulnerability is the function formApPortalWebAuth of the file /goform/apPortalAuth. The...
NA - CVE-2024-7553 - Incorrect validation of files loaded from a...
Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Windows. This may result in the application...
High - CVE-2024-6522 - The Modern Events Calendar plugin for WordPress...
The Modern Events Calendar plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.12.1 via the 'mec_fes_form' AJAX function. This makes...
NA - CVE-2024-7265 - Incorrect User Management vulnerability in...
Incorrect User Management vulnerability in Naukowa i Akademicka Sie? Komputerowa - Pa?stwowy Instytut Badawczy EZD RP allows logged-in user to change the password of any user, including root user,...
NA - CVE-2024-7266 - Incorrect User Management vulnerability in...
Incorrect User Management vulnerability in Naukowa i Akademicka Sie? Komputerowa - Pa?stwowy Instytut Badawczy EZD RP allows logged-in user to list all users in the system, including those from...
NA - CVE-2024-7267 - Exposure of Sensitive Information vulnerability...
Exposure of Sensitive Information vulnerability in Naukowa i Akademicka Sie? Komputerowa - Pa?stwowy Instytut Badawczy EZD RP allows logged-in user to retrieve information about IP infrastructure...
NA - CVE-2024-7353 - The Accept Stripe Payments plugin for WordPress...
The Accept Stripe Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's accept_stripe_payment_ng shortcode in all versions up to, and including, 2.0.86...
Medium - CVE-2024-7355 - The Organization chart plugin for WordPress is...
The Organization chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_input’ and 'node_description' parameter in all versions up to, and including, 1.5.0...