NA - CVE-2024-7506 - A vulnerability has been found in itsourcecode...
A vulnerability has been found in itsourcecode Tailoring Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /setlogo.php. The...
Medium - CVE-2024-5708 - The WPBakery Visual Composer plugin for...
The WPBakery Visual Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in all versions up to, and including, 7.7 due to insufficient input...
High - CVE-2024-5709 - The WPBakery Visual Composer plugin for...
The WPBakery Visual Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.7 via the 'layout_name' parameter. This makes it possible...
NA - CVE-2024-6200 - HaloITSM versions up to 2.146.1 are affected by...
HaloITSM versions up to 2.146.1 are affected by a Stored Cross-Site Scripting (XSS) vulnerability. The injected JavaScript code can execute arbitrary action on behalf of the user accessing a...
NA - CVE-2024-6201 - HaloITSM versions up to 2.146.1 are affected by...
HaloITSM versions up to 2.146.1 are affected by a Template Injection vulnerability within the engine used to generate emails. This can lead to the leakage of potentially sensitive information....
NA - CVE-2024-6202 - HaloITSM versions up to 2.146.1 are affected by...
HaloITSM versions up to 2.146.1 are affected by a SAML XML Signature Wrapping (XSW) vulnerability. When having a SAML integration configured, anonymous actors could impersonate arbitrary HaloITSM...
NA - CVE-2024-6203 - HaloITSM versions up to 2.146.1 are affected by...
HaloITSM versions up to 2.146.1 are affected by a Password Reset Poisoning vulnerability. Poisoned password reset links can be sent to existing HaloITSM users (given their email address is known)....
NA - CVE-2024-6651 - The WordPress File Upload WordPress plugin...
The WordPress File Upload WordPress plugin before 4.24.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be...
NA - CVE-2024-6766 - The shortcodes-ultimate-pro WordPress plugin...
The shortcodes-ultimate-pro WordPress plugin before 7.2.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed,...
NA - CVE-2024-7055 - A vulnerability was found in FFmpeg up to...
A vulnerability was found in FFmpeg up to 7.0.1. It has been classified as critical. This affects the function pnm_decode_frame in the library /libavcodec/pnmdec.c. The manipulation leads to...