NA - CVE-2024-45317 - A Server-Side Request Forgery (SSRF)...
A Server-Side Request Forgery (SSRF) vulnerability in SMA1000 appliance firmware versions 12.4.3-02676 and earlier allows a remote, unauthenticated attacker to cause the SMA1000 server-side...
NA - CVE-2024-48987 - Snipe-IT before 7.0.10 allows remote code...
Snipe-IT before 7.0.10 allows remote code execution (associated with cookie serialization) when an attacker knows the APP_KEY. This is exacerbated by .env files, available from the product's...
NA - CVE-2024-5005 - An issue has been discovered discovered in...
An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 11.4 before 17.2.9, all versions starting from 17.3 before 17.3.5, all versions starting from 17.4...
NA - CVE-2024-6971 - A path traversal vulnerability exists in the...
A path traversal vulnerability exists in the parisneo/lollms-webui repository, specifically in the `lollms_file_system.py` file. The functions `add_rag_database`, `toggle_mount_rag_database`, and...
Medium - CVE-2024-7514 - The WordPress Comments Import & Export plugin...
The WordPress Comments Import & Export plugin for WordPress is vulnerable to to arbitrary file read due to insufficient file path validation during the comments import process, in versions up to,...
Medium - CVE-2024-8913 - The The Plus Addons for Elementor – Elementor...
The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and...
NA - CVE-2024-8970 - An issue was discovered in GitLab CE/EE...
An issue was discovered in GitLab CE/EE affecting all versions starting from 11.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows an...
Medium - CVE-2024-9051 - The WP Ultimate Post Grid plugin for WordPress...
The WP Ultimate Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpupg-grid-with-filters shortcode in all versions up to, and including, 3.9.3 due...
NA - CVE-2024-9164 - An issue was discovered in GitLab EE affecting...
An issue was discovered in GitLab EE affecting all versions starting from 12.5 prior to 17.2.9, starting from 17.3, prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows running...
Medium - CVE-2024-9211 - The FULL – Cliente plugin for WordPress is...
The FULL – Cliente plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up...