9.8
CVE-2024-53913 -
An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24343. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.
9.8
CVE-2024-53912 -
An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24341. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.
4.3
CVE-2024-35160 - IBM Watson Query on Cloud Pak for Data and IBM Db2 Big SQL on Cloud Pak for Data information discloโฆ
IBM Watson Query on Cloud Pak for Data 1.8, 2.0, 2.1, 2.2ย and IBM Db2 Big SQL on Cloud Pak for Data 7.3, 7.4, 7.5, and 7.6ย could allow an authenticated user to obtain sensitive information due to insufficient session expiration.
6.9
CVE-2024-11632 - code-projects Simple Car Rental System book_car.php sql injection
A vulnerability was found in code-projects Simple Car Rental System 1.0. It has been classified as critical. Affected is an unknown function of the file /book_car.php. The manipulation of the argument fname/id_no/gender/email/phone/location leads to sql injection. It is possible to launch the attacโฆ
5.3
CVE-2023-7299 - DataGear resolveSql sql injection
A vulnerability was found in DataGear up to 4.60. It has been declared as critical. This vulnerability affects unknown code of the file /dataSet/resolveSql. The manipulation of the argument sql leads to sql injection. The attack can be initiated remotely. Upgrading to version 4.7.0 is able to addreโฆ
6.4
CVE-2024-11228 - ์๋ํ๋ ์ค ๊ฒฐ์ ์ฌํํ์ด โ ์ฐ์ปค๋จธ์ค ๊ฒฐ์ ํ๋ฌ๊ทธ์ธ <= 5.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting paโฆ
The ์๋ํ๋ ์ค ๊ฒฐ์ ์ฌํํ์ด โ ์ฐ์ปค๋จธ์ค ๊ฒฐ์ ํ๋ฌ๊ทธ์ธ plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's pafw_instant_payment shortcode in all versions up to, and including, 5.1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possibโฆ
6.4
CVE-2024-11229 - ์ฝ๋์ ์ต ์์ ํก <= 1.1.18 - Authenticated (Contributor+) Stored Cross-Site Scripting via add_plus_friends โฆ
The ์ฝ๋์ ์ต ์์ ํก plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's add_plus_friends and add_plus_talk shortcodes in all versions up to, and including, 1.1.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible fโฆ
5.3
CVE-2024-11631 - itsourcecode Tailoring Management System expedit.php sql injection
A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /expedit.php. The manipulation of the argument expcat leads to sql injection. The attack may be initiated remotely. The exploit has been disclโฆ
6.4
CVE-2024-11231 - ์ฐ์ปค๋จธ์ค ๋ค์ด๋ฒํ์ด <= 3.3.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via mnp_purchase Shoโฆ
The ์ฐ์ปค๋จธ์ค ๋ค์ด๋ฒํ์ด plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mnp_purchase shortcode in all versions up to, and including, 3.3.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacโฆ
7.3
CVE-2024-11034 - Request a Quote for WooCommerce and Elementor โ Get a Quote Button โ Product Enquiry Form Popup โ Pโฆ
The The Request a Quote for WooCommerce and Elementor โ Get a Quote Button โ Product Enquiry Form Popup โ Product Quotation plugin for WordPress is vulnerable to arbitrary shortcode execution via fire_contact_form AJAX action in all versions up to, and including, 1.4. This is due to the software alโฆ