7.6
CVE-2024-56335 - Privilege escalation allows organization groups to be updated/deleted if their UUID is known in vauโฆ
vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. In affected versions an attacker is capable of updating or deleting groups from an organization given a few conditions: 1. The attacker has a user account in the server. 2. The attacker's accouโฆ
7.8
CVE-2024-56334 - Command injection vulnerability in getWindowsIEEE8021x (SSID) function in systeminformation
systeminformation is a System and OS information library for node.js. In affected versions SSIDs are not sanitized when before they are passed as a parameter to cmd.exe in the `getWindowsIEEE8021x` function. This means that malicious content in the SSID can be executed as OS commands. This vulnerabโฆ
9.3
CVE-2024-56330 - Session VNC may be accessed by other sessions on the same host in stardust
Stardust is a platform for streaming isolated desktop containers. With this exploit, inter container communication (ICC) is not disabled. This would allow users within a container to access another containers agent, therefore compromising access.The problem has been patched in any Stardust build paโฆ
6.9
CVE-2024-12842 - Emlog Pro user.php cross site scripting
A vulnerability was found in Emlog Pro up to 2.4.1. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/user.php. The manipulation of the argument keyword leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed โฆ
8.9
CVE-2024-56329 - Account Takeover Vulnerability in Social Account Linking in joelbutcher/socialstream
Socialstream is a third-party package for Laravel Jetstream. It replaces the published authentication and profile scaffolding provided by Laravel Jetstream, with scaffolding that has support for Laravel Socialite. When linking a social account to an already authenticated user, the lack of a confirmโฆ
9.4
CVE-2024-56333 - Remote code execution in onyxia-api
Onyxia is a web app that aims at being the glue between multiple open source backend technologies to provide a state of art working environment for data scientists. This critical vulnerability allows authenticated users to remotely execute code within the Onyxia-API, leading to potential consequencโฆ
6.8
CVE-2024-56331 - Local File Inclusion (LFI) via Improper URL Handling in uptime-kuma's `Real-Browser` monitor
Uptime Kuma is an open source, self-hosted monitoring tool. An **Improper URL Handling Vulnerability** allows an attacker to access sensitive local files on the server by exploiting the `file:///` protocol. This vulnerability is triggered via the **"real-browser"** request type, which takes a screeโฆ
8.8
CVE-2024-12867 - Server-Side Request Forgery in Arctic Hub URL Mapper allows an unauthenticated remote attacker to eโฆ
Server-Side Request Forgery in URL Mapper in Arctic Security's Arctic Hub versions 3.0.1764-5.6.1877 allows an unauthenticated remote attacker to exfiltrate and modify configurations and data.
6.9
CVE-2024-12841 - Emlog Pro tag.php cross site scripting
A vulnerability was found in Emlog Pro up to 2.4.1. It has been classified as problematic. This affects an unknown part of the file /admin/tag.php. The manipulation of the argument keyword leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed โฆ
8.5
CVE-2024-12677 - Delta Electronics DTM Soft Deserialization of Untrusted Data
Delta Electronics DTM Soft deserializes objects, which could allow an attacker to execute arbitrary code.