Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-12-16 CVE-2024-12654 NULL Pointer Dereference vulnerability in Fabulatech USB Over Network 6.0.6.1
A vulnerability classified as problematic was found in FabulaTech USB over Network 6.0.6.1.
local
low complexity
fabulatech CWE-476
5.5
2024-12-16 CVE-2024-54355 Cross-Site Request Forgery (CSRF) vulnerability in Wpmailster WP Mailster
Cross-Site Request Forgery (CSRF) vulnerability in brandtoss WP Mailster allows Cross Site Request Forgery.This issue affects WP Mailster: from n/a through 1.8.17.0.
network
low complexity
wpmailster CWE-352
8.8
2024-12-16 CVE-2024-54367 Deserialization of Untrusted Data vulnerability in Ultimatemember Forumwp
Deserialization of Untrusted Data vulnerability in ForumWP ForumWP allows Object Injection.This issue affects ForumWP: from n/a through 2.1.0.
network
low complexity
ultimatemember CWE-502
critical
9.8
2024-12-16 CVE-2024-54382 Path Traversal vulnerability in Bold-Themes Bold Page Builder
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in BoldThemes Bold Page Builder allows Path Traversal.This issue affects Bold Page Builder: from n/a through 5.1.5.
network
low complexity
bold-themes CWE-22
4.9
2024-12-16 CVE-2024-12641 TenderDocTransfer from Chunghwa Telecom has a Reflected Cross-site scripting vulnerability.
network
low complexity
CWE-79
critical
9.6
2024-12-16 CVE-2024-12642 TenderDocTransfer from Chunghwa Telecom has an Arbitrary File Write vulnerability.
network
low complexity
CWE-23
8.1
2024-12-16 CVE-2024-12643 The tbm-client from Chunghwa Telecom has an Arbitrary File Delete vulnerability.
network
low complexity
CWE-36
8.1
2024-12-16 CVE-2024-12644 The tbm-client from Chunghwa Telecom has an Arbitrary File vulnerability.
network
low complexity
CWE-36
7.1
2024-12-16 CVE-2024-12645 The topm-client from Chunghwa Telecom has an Arbitrary File Read vulnerability.
network
low complexity
CWE-23
6.5
2024-12-16 CVE-2024-12646 The topm-client from Chunghwa Telecom has an Arbitrary File Delete vulnerability.
network
low complexity
CWE-36
8.1