6.8
CVE-2024-56137 - MaxKB RCE vulnerability in function library
MaxKB, which stands for Max Knowledge Base, is an open source knowledge base question-answering system based on a large language model and retrieval-augmented generation (RAG). Prior to version 1.9.0, a remote command execution vulnerability exists in the module of function library. The vulnerabiliβ¦
4.3
CVE-2022-43476 - WordPress Subscribe to Category Plugin <= 2.7.4 is vulnerable to Broken Access Control
Missing Authorization vulnerability in Daniel SΓΆderstrΓΆm / Sidney van de Stouwe Subscribe to Category allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subscribe to Category: from n/a through 2.7.4.
4.3
CVE-2023-47778 - WordPress LuckyWP Scripts Control plugin <= 1.2.1 - Broken Access Control vulnerability
Missing Authorization vulnerability in LuckyWP LuckyWP Scripts Control allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LuckyWP Scripts Control: from n/a through 1.2.1.
4.3
CVE-2023-47807 - WordPress 10WebAnalytics plugin <= 1.2.12 - Broken Access Control vulnerability
Missing Authorization vulnerability in 10Web 10WebAnalytics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 10WebAnalytics: from n/a through 1.2.12.
5.3
CVE-2023-48739 - WordPress Porto Theme Functionality plugin < 2.12.1 - Broken Access Control vulnerability
Missing Authorization vulnerability in Porto Theme Porto Theme - Functionality allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Porto Theme - Functionality: from n/a before 2.12.1.
5.5
CVE-2024-49385 -
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis True Image (Windows) before build 41736, Acronis True Image OEM (Windows) before build 42575.
4
CVE-2024-55538 -
Sensitive information disclosure due to missing authentication. The following products are affected: Acronis True Image (macOS) before build 41725, Acronis True Image (Windows) before build 41736, Acronis True Image OEM (macOS) before build 42571, Acronis True Image OEM (Windows) before build 42575.
7.1
CVE-2023-48758 - WordPress JetEngine plugin <= 3.2.4 - Broken Access Control vulnerability
Missing Authorization vulnerability in Crocoblock JetEngine allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetEngine: from n/a through 3.2.4.
6.3
CVE-2024-13111 - Beijing Yunfan Internet Technology Yunfan Learning Examination System JWT Token SysUserControl imprβ¦
A vulnerability classified as critical was found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Affected by this vulnerability is an unknown functionality of the file src/main/java/com/yf/exam/modules/sys/user/controller/SysUserControl of the component JWT Token Hanβ¦
0.0
CVE-2024-37237 - WordPress FS Poster plugin <= 6.5.8 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in fs-code FS Poster fs-poster allows Cross Site Request Forgery.This issue affects FS Poster: from n/a through <= 6.5.8.