5.3
CVE-2024-12413 - MarketKing β Ultimate WooCommerce Multivendor Marketplace Solution <= 2.0.00 - Missing Authorization
The MarketKing β Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several functions like 'marketking_delete_team_member', 'marketkingrejectuser', 'marketking_save_profile_settings', and many more in aβ¦
6.5
CVE-2024-12032 - Tourfic β Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerceβ¦
The Tourfic β Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking plugin for WordPress is vulnerable to SQL Injection via the 'enquiry_id' parameter of the 'tf_enquiry_reply_email_callback' function in all versions up to, and including, 2.15.3 due to inβ¦
8.7
CVE-2024-1609 - OPPO Store APP has a WebView component privilege escalation vulnerability.
In OPPOStore iOS App, there's a possible escalation of privilege due to improper input validation.
9.8
CVE-2024-56431 - libtheora: incorrect bitwise shift in huffdec.c
oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parties because there is no evidence of a security impact, e.g., an application would not crash.
2.9
CVE-2024-56430 -
OpenFHE through 1.2.3 has a NULL pointer dereference in BinFHEContext::EvalFloor in lib/binfhe-base-scheme.cpp.
8.2
CVE-2019-2483 -
Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network accesβ¦
8.6
CVE-2024-12746 - SQL Injection in the Amazon Redshift ODBC Driver affecting v2.1.5.0
A SQL injection in the Amazon Redshift ODBC Driver v2.1.5.0 (Windows or Linux) allows a user to gain escalated privileges via the SQLTables or SQLColumns Metadata APIs. Users are recommended to upgrade to the driver version 2.1.6.0 or revert to driver version 2.1.4.0.
8.6
CVE-2024-12745 - SQL Injection in the Amazon Redshift Python Connector affecting v2.1.4
A SQL injection in the Amazon Redshift Python Connector v2.1.4 allows a user to gain escalated privileges via the get_schemas, get_tables, or get_columns Metadata APIs. Users are recommended to upgrade to the driver version 2.1.5 or revert to driver version 2.1.3.
8.6
CVE-2024-12744 - SQL Injection in the Amazon Redshift JDBC Driver affecting v2.1.0.31
A SQL injection in the Amazon Redshift JDBC Driver in v2.1.0.31 allows a user to gain escalated privileges via the getSchemas, getTables, or getColumns Metadata APIs. Users should upgrade to the driver version 2.1.0.32 or revert to driver version 2.1.0.30.
9.8
CVE-2024-43441 - Apache HugeGraph-Server: Fixed JWT Token(Secret)
Authentication Bypass by Assumed-Immutable Data vulnerability in Apache HugeGraph-Server. This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.5.0. Users are recommended to upgrade to version 1.5.0, which fixes the issue.