NA - CVE-2024-12700 - There is an unrestricted file upload...
There is an unrestricted file upload vulnerability where it is possible for an authenticated user (low privileged) to upload an jsp shell and execute code with the privileges of user running the...
NA - CVE-2024-54009 - Remote authentication bypass vulnerability in...
Remote authentication bypass vulnerability in HPE Alletra Storage MP B10000 in versions prior to version 10.4.5 could be remotely exploited to allow disclosure of information.
NA - CVE-2024-54663 - An issue was discovered in the Webmail Classic...
An issue was discovered in the Webmail Classic UI in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Local File Inclusion (LFI) vulnerability exists in the /h/rest endpoint, allowing...
NA - CVE-2024-56327 - pyrage is a set of Python bindings for the rage...
pyrage is a set of Python bindings for the rage file encryption library (age in Rust). `pyrage` uses the Rust `age` crate for its underlying operations, and `age` is vulnerable to...
Medium - CVE-2024-11439 - The ScanCircle plugin for WordPress is...
The ScanCircle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'scancircle' shortcode in all versions up to, and including, 2.9.2 due to...
Medium - CVE-2024-11748 - The Taeggie Feed plugin for WordPress is...
The Taeggie Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'taeggie-feed' shortcode in all versions up to, and including, 0.1.9 due to...
Medium - CVE-2024-11881 - The Easy Waveform Player plugin for WordPress...
The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'easywaveformplayer' shortcode in all versions up to, and including, 1.2.0...
Medium - CVE-2024-12500 - The Philantro – Donations and Donor Management...
The Philantro – Donations and Donor Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes like 'donate' in all versions up to, and...