NA - CVE-2024-6040 - In parisneo/lollms-webui version v9.8, the...
In parisneo/lollms-webui version v9.8, the lollms_binding_infos is missing the client_id parameter, which leads to multiple security vulnerabilities. Specifically, the endpoints /reload_binding,...
NA - CVE-2024-6242 - A vulnerability exists in Rockwell Automation...
A vulnerability exists in Rockwell Automation affected products that allows a threat actor to bypass the Trusted® Slot feature in a ControlLogix® controller. If exploited on any affected module in...
NA - CVE-2024-6873 - It is possible to crash or redirect the...
It is possible to crash or redirect the execution flow of the ClickHouse server process from an unauthenticated vector by sending a specially crafted request to the ClickHouse server native...
NA - CVE-2024-23600 - Improper Input Validation of query search...
Improper Input Validation of query search results for private field data in PingIDM OPENIDM (Query Filter module) allows for a potentially efficient brute forcing approach leading to information...
NA - CVE-2024-41962 - Bostr is an nostr relay aggregator proxy that...
Bostr is an nostr relay aggregator proxy that acts like a regular nostr relay. bostr let everyone in even having authorized_keys being set when noscraper is set to true. This vulnerability is fixed...
NA - CVE-2024-7211 - The Identity Server used by 1E Platform could...
The Identity Server used by 1E Platform could enable URL redirection to untrusted sites. Note: The Identity Server on 1E Platform has been updated with the necessary patch.
NA - CVE-2024-7359 - A vulnerability was found in SourceCodester...
A vulnerability was found in SourceCodester Tracking Monitoring Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file...
Medium - CVE-2024-6346 - The Gutenberg Blocks, Page Builder –...
The Gutenberg Blocks, Page Builder – ComboBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the redirectURL parameter of the Date Countdown widget, in all versions up to,...
Medium - CVE-2024-2455 - The Element Pack - Addon for Elementor Page...
The Element Pack - Addon for Elementor Page Builder WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget wrapper link URL in all versions up to, and...
NA - CVE-2024-7357 - ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability...
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-600 up to 2.18. It has been rated as critical. This issue affects the function soapcgi_main of the file /soap.cgi. The...