NA - CVE-2024-21542 - Versions of the package luigi before 3.6.0 are...
Versions of the package luigi before 3.6.0 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) due to improper destination file path validation in the _extract_packages_archive...
High - CVE-2023-6947 - The Best WordPress Gallery Plugin – FooGallery...
The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.26. This makes it possible for authenticated...
NA - CVE-2024-10708 - The System Dashboard WordPress plugin before...
The System Dashboard WordPress plugin before 2.8.15 does not validate user input used in a path, which could allow high privilege users such as admin to perform path traversal attacks an read...
NA - CVE-2024-11107 - The System Dashboard WordPress plugin before...
The System Dashboard WordPress plugin before 2.8.15 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated users to perform Cross-Site...
NA - CVE-2024-28138 - An unauthenticated attacker with network access...
An unauthenticated attacker with network access to the affected device's web interface can execute any system command via the "msg_events.php" script as the www-data user. The HTTP GET...
NA - CVE-2024-47946 - If the attacker has access to a valid Poweruser...
If the attacker has access to a valid Poweruser session, remote code execution is possible because specially crafted valid PNG files with injected PHP content can be uploaded as desktop backgrounds...
Medium - CVE-2024-11940 - The Property Hive Mortgage Calculator plugin...
The Property Hive Mortgage Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘price’ parameter in all versions up to, and including, 1.0.6 due to insufficient...
Medium - CVE-2024-45709 - SolarWinds Web Help Desk was susceptible to a...
SolarWinds Web Help Desk was susceptible to a local file read vulnerability. This vulnerability requires the software be installed on Linux and configured to use non-default development/test mode...
NA - CVE-2024-8256 - In Teltonika Networks RUTOS devices, running on...
In Teltonika Networks RUTOS devices, running on versions 7.0 to 7.8 (excluding) and TSWOS devices running on versions 1.0 to 1.3 (excluding), due to incorrect permission handling a vulnerability...
Medium - CVE-2024-11945 - The Email Reminders plugin for WordPress is...
The Email Reminders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 2.0.4 due to insufficient input sanitization and...