7.6
CVE-2024-30246 - Tuleap deleting or moving an artifact can delete values from unrelated artifacts
Tuleap is an Open Source Suite to improve management of software developments and collaboration. A malicious user could exploit this issue on purpose to delete information on the instance or possibly gain access to restricted artifacts. It is however not possible to control exactly which informatioβ¦
6.5
CVE-2024-30513 - WordPress ProfileGrid plugin <= 5.7.2 - Insecure Direct Object References (IDOR) vulnerability
Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.2.
5.3
CVE-2024-30469 - WordPress Wholesale For WooCommerce plugin <= 2.3.0 - Unauthenticated Sensitive Data Exposure vulneβ¦
Missing Authorization vulnerability in WPExperts Wholesale For WooCommerce.This issue affects Wholesale For WooCommerce: from n/a through 2.3.0.
5.3
CVE-2024-30511 - WordPress FG PrestaShop to WooCommerce plugin <= 4.45.1 - Sensitive Data Exposure via Log File vulnβ¦
Insertion of Sensitive Information into Log File vulnerability in FrΓ©dΓ©ric GILLES FG PrestaShop to WooCommerce.This issue affects FG PrestaShop to WooCommerce: from n/a through 4.45.1.
5.3
CVE-2024-30514 - WordPress Paid Memberships Pro β Payfast Gateway Add On plugin <= 1.4.1 - Sensitive Data Exposure vβ¦
Insertion of Sensitive Information into Log File vulnerability in Paid Memberships Pro Paid Memberships Pro β Payfast Gateway Add On.This issue affects Paid Memberships Pro β Payfast Gateway Add On: from n/a through 1.4.1.
4.3
CVE-2024-30492 - WordPress Export and Import Users and Customers plugin <= 2.5.2 - Path Traversal vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WebToffee Import Export WordPress Users.This issue affects Import Export WordPress Users: from n/a through 2.5.2.
7.5
CVE-2024-29904 - CodeIgniter4 Language class DoS Vulnerability
CodeIgniter is a PHP full-stack web framework A vulnerability was found in the Language class that allowed DoS attacks. This vulnerability can be exploited by an attacker to consume a large amount of memory on the server. Upgrade to v4.4.7 or later.
4.8
CVE-2024-29901 - @workos-inc/authkit-nextjs session replay vulnerability
The AuthKit library for Next.js provides helpers for authentication and session management using WorkOS & AuthKit with Next.js. A user can reuse an expired session by controlling the `x-workos-session` header. The vulnerability is patched in v0.4.2.
7.5
CVE-2024-29900 - @electron/packager's build process memory potentially leaked into final executable
Electron Packager bundles Electron-based application source code with a renamed Electron executable and supporting files into folders ready for distribution. A random segment of ~1-10kb of Node.js heap memory allocated either side of a known buffer will be leaked into the final executable. This memβ¦
8.8
CVE-2024-29890 - Remote code execution in datalens-ui
DataLens is a business intelligence and data visualization system. A specifically crafted request allowed the creation of a special chart type with the ability to pass custom javascript code that would later be executed in an unprotected sandbox on subsequent requests to that chart. The problem wasβ¦