6.5
CVE-2024-50651 -
java_shop 1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter.
5.9
CVE-2024-24452 -
An invalid memory access when handling the ProtocolIE_ID field ofย E-RAB Release Indication messages in Athonet vEPC MME v11.4.0ย allows attackers to cause a Denial of Service (DoS) to the cellularย network by repeatedly initiating connections and sending a craftedย payload.
9.8
CVE-2024-50649 -
The user avatar upload function in python_book V1.0 has an arbitrary file upload vulnerability.
6.1
CVE-2024-50983 -
FlightPath 7.5 contains a Cross Site Scripting (XSS) vulnerability, which allows authenticated remote attackers with administrative rights to inject arbitrary JavaScript in the web browser of a user by including a malicious payload into the Last Name section in the Create/Edit Faculty/Staff User orโฆ
7.5
CVE-2024-45969 -
NULL pointer dereference in the MMS Client in MZ Automation LibIEC1850 before commit 7afa40390b26ad1f4cf93deaa0052fe7e357ef33 allows a malicious server to Cause a Denial-of-Service via the MMS InitiationResponse message.
6.5
CVE-2024-24446 -
An uninitialized pointer dereference in OpenAirInterface CN5G AMF up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a crafted InitialContextSetupResponse message sent to the AMF.
9.8
CVE-2024-45970 -
Multiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit ac925fae8e281ac6defcd630e9dd756264e9c5bc allow a malicious server to cause a stack-based buffer overflow via the MMS FileDirResponse message.
7.3
CVE-2024-50986 -
An issue in Clementine v.1.3.1 allows a local attacker to execute arbitrary code via a crafted DLL file.
6.1
CVE-2024-50800 -
Cross Site Scripting vulnerability in M2000 Smart4Web before v.5.020241004 allows a remote attacker to execute arbitrary code via the error parameter in URL
7.8
CVE-2024-46465 -
By default, dedicated folders of CRYHOD for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of CRYHOD has to be modified to prevent this vulnerability.