NA - CVE-2024-45845 - nix 2.24 through 2.24.5 allows directory...
nix 2.24 through 2.24.5 allows directory traversal via a symlink in a nar file, because of mishandling of a directory containing a symlink and a directory of the same name, aka GHSA-h4vv-h3jq-v493.
High - CVE-2024-7770 - The Bit File Manager – 100% Free & Open Source...
The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the...
Medium - CVE-2024-6282 - The Master Addons – Free Widgets, Hover...
The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-jltma-wrapper-link...
Medium - CVE-2024-8369 - The EventPrime – Events Calendar, Bookings and...
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access to Private or Password-protected events due to missing authorization checks in all...
NA - CVE-2024-37728 - Arbitrary File Read vulnerability in Xi'an...
Arbitrary File Read vulnerability in Xi'an Daxi Information Technology Co., Ltd OfficeWeb365 v.7.18.23.0 and v8.6.1.0 allows a remote attacker to obtain sensitive information via the...