High - CVE-2024-40721 - The specific API in TCBServiSign Windows...
The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-side input. When a user visits a spoofed website, unauthenticated remote...
Medium - CVE-2024-40722 - The specific API in TCBServiSign Windows...
The specific API in TCBServiSign Windows Version from CHANGING Information Technology does does not properly validate the length of server-side input. When a user visits a spoofed website,...
Medium - CVE-2024-40723 - The specific API in HWATAIServiSign Windows...
The specific API in HWATAIServiSign Windows Version from CHANGING Information Technology does not properly validate the length of server-side inputs. When a user visits a spoofed website,...
Medium - CVE-2024-6704 - The Comments – wpDiscuz plugin for WordPress is...
The Comments – wpDiscuz plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 7.6.21. This is due to a lack of filtering of HTML tags in comments. This makes it...
Medium - CVE-2024-7204 - Ai3 QbiBot does not properly filter user input,...
Ai3 QbiBot does not properly filter user input, allowing unauthenticated remote attackers to insert JavaScript code into the chat box. Once the recipient views the message, they will be subject to...
Medium - CVE-2024-7323 - Digiwin EasyFlow .NET lacks proper access...
Digiwin EasyFlow .NET lacks proper access control for specific functionality, and the functionality do not adequately filter user input. A remote attacker with regular privilege can exploit this...
NA - CVE-2024-38890 - An issue in Horizon Business Services Inc....
An issue in Horizon Business Services Inc. Caterease Software 16.0.1.1663 through 24.0.1.2405 and possibly later versions allows a local attacker to perform an Authentication Bypass by...
NA - CVE-2024-41127 - Monkeytype is a minimalistic and customizable...
Monkeytype is a minimalistic and customizable typing test. Monkeytype is vulnerable to Poisoned Pipeline Execution through Code Injection in its ci-failure-comment.yml GitHub Workflow, enabling...