NA - CVE-2024-12901 - A vulnerability classified as critical was...
A vulnerability classified as critical was found in FoxCMS up to 1.2. Affected by this vulnerability is an unknown functionality of the file /app/api/controller/Site.php of the component API...
Medium - CVE-2024-11230 - The Elementor Header & Footer Builder plugin...
The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘size’ parameter in all versions up to, and including, 1.6.46 due to insufficient...
High - CVE-2024-12902 - ANCHOR from Global Wisdom Software is an...
ANCHOR from Global Wisdom Software is an integrated product running on a Windows virtual machine. The underlying Windows OS of the product contains high-privilege service accounts. If these...
NA - CVE-2024-12903 - Incorrect default permissions vulnerability in...
Incorrect default permissions vulnerability in Evoko Home, affecting version 2.4.2 to 2.7.4. A non-admin user could exploit weak file and folder permissions to escalate privileges, execute...
NA - CVE-2024-23945 - Signing cookies is an application security...
Signing cookies is an application security feature that adds a digital signature to cookie data to verify its authenticity and integrity. The signature helps prevent malicious actors from modifying...
NA - CVE-2024-45387 - An SQL injection vulnerability in Traffic Ops...
An SQL injection vulnerability in Traffic Ops in Apache Traffic Control = 8.0.0 allows a privileged user with role "admin", "federation", "operations", "portal", or "steering" to execute arbitrary...
NA - CVE-2024-53256 - Rizin is a UNIX-like reverse engineering...
Rizin is a UNIX-like reverse engineering framework and command-line toolset. `rizin.c` still had an old snippet of code which suffered a command injection due the usage of `rz_core_cmdf` to invoke...
NA - CVE-2024-54148 - Gogs is an open source self-hosted Git service....
Gogs is an open source self-hosted Git service. A malicious user is able to commit and edit a crafted symlink file to a repository to gain SSH access to the server. The vulnerability is fixed in...
NA - CVE-2024-55947 - Gogs is an open source self-hosted Git service....
Gogs is an open source self-hosted Git service. A malicious user is able to write a file to an arbitrary path on the server to gain SSH access to the server. The vulnerability is fixed in 0.13.1.