NA - CVE-2024-8096 - When curl is told to use the Certificate Status...
When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems...
NA - CVE-2024-45786 - This vulnerability exists in Reedos aiM-Star...
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to improper access controls on its certain API endpoints. An authenticated remote attacker could exploit this vulnerability by...
NA - CVE-2024-45787 - This vulnerability exists in Reedos aiM-Star...
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to transmission of sensitive information in plain text in certain API endpoints. An authenticated remote attacker could exploit this...
NA - CVE-2024-45788 - This vulnerability exists in Reedos aiM-Star...
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing rate limiting on OTP requests in certain API endpoints. An authenticated remote attacker could exploit this vulnerability...
NA - CVE-2024-45789 - This vulnerability exists in Reedos aiM-Star...
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to improper validation of the ‘mode’ parameter in the API endpoint used during the registration process. An authenticated remote...
Medium - CVE-2024-5416 - The Elementor Website Builder – More than Just...
The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url parameter of multiple widgets in all versions up to, and...
NA - CVE-2024-7609 - Improper Limitation of a Pathname to a...
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Vidco Software VOC TESTER allows Path Traversal.This issue affects VOC TESTER: before 12.34.8.
NA - CVE-2024-45790 - This vulnerability exists in Reedos aiM-Star...
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this...
NA - CVE-2024-6091 - A vulnerability in significant-gravitas/autogpt...
A vulnerability in significant-gravitas/autogpt version 0.5.1 allows an attacker to bypass the shell commands denylist settings. The issue arises when the denylist is configured to block specific...
NA - CVE-2024-27112 - A unauthenticated SQL Injection has been found...
A unauthenticated SQL Injection has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use this vulnerability to gain access to the underlying...