A vulnerability was found in Post Grid Combo Plugin up to 2.2.68 on WordPress. It has been classified as problematic. Affected is the function get_posts of the component API Endpoint. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2023-7072. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability was found in Blossom Spa Plugin up to 1.3.4 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2024-2107. The attack can be launched remotely. There is no exploit available.
A vulnerability, which was classified as critical, was found in Gacjie Server up to 1.0. This affects the function index of the file /app/admin/controller/Upload.php. The manipulation of the argument file leads to unrestricted upload.
This vulnerability is uniquely identified as CVE-2024-2406. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability, which was classified as critical, was found in Apache Pulsar up to 2.10.5/2.11.2/3.0.1/3.1.0. Affected is an unknown function of the file /proxy-stats. The manipulation leads to missing authentication.
This vulnerability is traded as CVE-2022-34321. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Apache Pulsar up to 2.10.5/2.11.3/3.0.2/3.1.2/3.2.0 and classified as critical. Affected by this issue is some unknown functionality of the component Function Worker. The manipulation leads to dynamically-managed code resources.
This vulnerability is handled as CVE-2024-27135. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical has been found in code-projects Scholars Tracking System 1.0. This affects an unknown part of the component Eligibility Information Update. The manipulation leads to sql injection.
This vulnerability is uniquely identified as CVE-2024-24101. The attack needs to be initiated within the local network. There is no exploit available.