9.8
CVE-2024-10571 - Chartify β WordPress Chart Plugin <= 2.9.5 - Unauthenticated Local File Inclusion via source
The Chartify β WordPress Chart Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.5 via the 'source' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution β¦
7.5
CVE-2024-47916 - Boa web server - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversβ¦
Boa web server - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
7.5
CVE-2024-47915 - VaeMendis - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
VaeMendis - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
4.5
CVE-2024-47914 - VaeMendis - CWE-352: Cross-Site Request Forgery (CSRF)
VaeMendis - CWE-352: Cross-Site Request Forgery (CSRF)
9.1
CVE-2024-50306 - Apache Traffic Server: Server process can fail to drop privilege
Unchecked return value can allow Apache Traffic Server to retain privileges on startup. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5, from 10.0.0 through 10.0.1. Users are recommended to upgrade to version 9.2.6 or 10.0.2, which fixes the issue.
7.5
CVE-2024-50305 - Apache Traffic Server: Valid Host field value can cause crashes
Valid Host header field can cause Apache Traffic Server to crash on some platforms. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5. Users are recommended to upgrade to version 9.2.6, which fixes the issue, or 10.0.2, which does not have the issue.
7.5
CVE-2024-38479 - Apache Traffic Server: Cache key plugin is vulnerable to cache poisoning attack
Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.5. Users are recommended to upgrade to version 9.2.6, which fixes the issue, or 10.0.2, which does not have the issue.
7.5
CVE-2024-45254 - VaeMendis - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scriptβ¦
VaeMendis - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
7.5
CVE-2024-45253 - Avigilon β CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Avigilon β CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
8.7
CVE-2024-2550 - PAN-OS: Firewall Denial of Service (DoS) in GlobalProtect Gateway Using a Specially Crafted Packet
A null pointer dereference vulnerability in the GlobalProtect gateway in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop the GlobalProtect service on the firewall by sending a specially crafted packet that causes a denial of service (DoS) condition. Repeated attempts β¦