A vulnerability was found in Dynamic Web Lab Dynamic Product Category Grid, Slider for WooCommerce Plugin up to 1.1.3 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability is handled as CVE-2024-56230. The attack may be launched remotely. There is no exploit available.
A vulnerability classified as problematic has been found in W3 Eden Download Manager Plugin up to 3.3.03 on WordPress. Affected is an unknown function. The manipulation leads to missing authorization.
This vulnerability is traded as CVE-2024-56217. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability classified as problematic was found in MarketingFire Widget Options Plugin up to 4.0.6.1 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to missing authorization.
This vulnerability is known as CVE-2024-56219. The attack can be launched remotely. There is no exploit available.
A vulnerability was found in Progress WhatsUp Gold up to 2024.0.1 and classified as critical. This issue affects some unknown processing of the component HTTP Request Handler. The manipulation leads to path traversal.
The identification of this vulnerability is CVE-2024-12105. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Progress WhatsUp Gold up to 2024.0.1. It has been classified as critical. This affects an unknown part of the component LDAP Setting Handler. The manipulation leads to missing authentication.
This vulnerability is uniquely identified as CVE-2024-12106. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Progress WhatsUp Gold up to 2024.0.1. It has been declared as critical. This vulnerability affects unknown code of the component Public API. The manipulation leads to authentication bypass by spoofing.
This vulnerability was named CVE-2024-12108. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, was found in IBM Storage Scale Container Native Storage Access up to 5.1.7.0. This affects an unknown part of the component Container Handler. The manipulation leads to improper authentication.
This vulnerability is uniquely identified as CVE-2022-41738. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in IBM Storage Scale Container Native Storage Access up to 5.1.7.0 and classified as problematic. This issue affects some unknown processing. The manipulation leads to improper authentication.
The identification of this vulnerability is CVE-2022-41737. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in SuiteCRM 7.14.2. This issue affects some unknown processing. The manipulation leads to unrestricted upload.
The identification of this vulnerability is CVE-2024-1644. The attack may be initiated remotely. There is no exploit available.
A vulnerability, which was classified as very critical, has been found in Loomio 2.22.0. Affected by this issue is some unknown functionality. The manipulation leads to os command injection.
This vulnerability is handled as CVE-2024-1297. The attack may be launched remotely. There is no exploit available.
A vulnerability, which was classified as critical, was found in TemmokuMVC up to 2.3. Affected is the function get_img_url/img_replace in the library lib/images_get_down.php of the component Image Download Handler. The manipulation leads to deserialization.
This vulnerability is traded as CVE-2024-1750. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in IBM Aspera Console up to 3.4.2 and classified as critical. This issue affects some unknown processing. The manipulation leads to sql injection.
The identification of this vulnerability is CVE-2022-43842. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in kirby up to 4.1.0. It has been classified as problematic. This affects an unknown part of the component javascript URL Handler. The manipulation of the argument link leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-27087. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
Threat actors compromised at least 16 Chrome browser extensions leading to the exposure of data from over 600,000 users. A supply chain attack compromised 16 Chrome browser extensions, exposing over 600,000 users. Threat actors targeted the publishers of the extensions on the Chrome Web Store via phishing messages, then once obtained access to their account […]
A vulnerability has been found in Roxen Webserver 2.0.x and classified as critical. This vulnerability affects unknown code of the component URL Handler. The manipulation with the input %00 leads to improper privilege management.
This vulnerability was named CVE-2000-0671. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical was found in Samhain Labs hsftp up to 1.11. This vulnerability affects unknown code of the component LS Command Handler. The manipulation leads to format string.
This vulnerability was named CVE-2004-0159. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.