7.2
CVE-2024-54181 - IBM WebSphere Automation command injection
IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to execute arbitrary code. Using specially crafted input, the user could exploit this vulnerability to execute arbitrary code on the system.
9.3
CVE-2024-10044 - SSRF in POST /worker_generate_stream API endpoint in lm-sys/fastchat
A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API endpoint of the Controller API Server in lm-sys/fastchat, as of commit e208d5677c6837d590b81cb03847c0b9de100765. This vulnerability allows attackers to exploit the victim controller API server's credenβ¦
4.8
CVE-2024-12993 - Location information exposure in Infinix Weather app
Infinix devices contain a pre-loaded "com.rlk.weathers" application, that exposes an unsecured content provider. An attacker can communicate with the provider and reveal the userβs location without any privileges.Β After multiple attempts to contact the vendor we did not receive any answer. We suppβ¦
9.8
CVE-2024-47926 - Tecnick TCExam β CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Iβ¦
Tecnick TCExam β CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
7.5
CVE-2024-47925 - Tecnick TCExam β Multiple CWE-79: Improper Neutralization of Input During Web Page Generation ('Croβ¦
Tecnick TCExam β Multiple CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
7.5
CVE-2024-47924 - Boa web server β CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Sβ¦
Boa web server β CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
5.3
CVE-2024-47923 - Mashov β CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Mashov β CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
7.5
CVE-2024-47922 - Priority β CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Priority β CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
8.4
CVE-2024-47921 - Smadar SPS β CWE-327: Use of a Broken or Risky Cryptographic Algorithm
Smadar SPS β CWE-327: Use of a Broken or Risky Cryptographic Algorithm
7.5
CVE-2024-47920 - Tiki Wiki CMS β CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scβ¦
Tiki Wiki CMS β CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')