7.8
CVE-2024-10251 -
Under specific circumstances, insecure permissions in Ivanti Security Controls before version 2024.4.1 allows a local authenticated attacker to achieve local privilege escalation.
6.3
CVE-2024-28141 - Cross-Site Request-Forgery
The web application is not protected against cross-site request forgery attacks. Therefore, an attacker can trick users into performing actions on the application when they visit an attacker-controlled website or click on a malicious link. E.g. an attacker can forge malicious links to reset the admโฆ
7.6
CVE-2024-47758 - GLPI vulnerable to account takeover without privilege escalation through the API
GLPI is a free asset and IT management software package. Starting in version 9.3.0 and prior to version 10.0.17, an authenticated user can use the API to take control of any user that have the same or a lower level of privileges. Version 10.0.17 contains a patch for this issue.
6.1
CVE-2024-28140 - Violation of Least Privilege Principle
The scanner device boots into a kiosk mode by default and opens the Scan2Net interface in a browser window. This browser is run with the permissions of the root user. There are also several other applications running as root user.ย This can be confirmed by running "ps aux" as the root user and obserโฆ
8.8
CVE-2024-28139 - Privilege escalation through sudo misconfiguration
The www-data user can elevate its privileges because sudo is configured to allow the execution of the mount command as root without a password. Therefore, the privileges can be escalated to the root user. The risk has been accepted by the vendor and won't be fixed in the near future.
9.5
CVE-2024-53677 - Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload cheโฆ
File upload logic in Apache Struts is flawed.ย An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. This issue affects Apache Struts: from 2.0.0 before 6.4โฆ
4.7
CVE-2024-50585 - Reflected Cross-Site Scripting
Users who click on a malicious link or visit a website under the control of an attacker can be infected with arbitrary JavaScript which is running in the context of the "Numerix License Server Administration System Login" (nlslogin.jsp) page.ย The vulnerability can be triggered by sending a speciallโฆ
0.0
CVE-2024-12498 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
5.3
CVE-2024-11351 - Restrict โ membership, site, content and user access restrictions for WordPress <= 2.2.8 - Unauthenโฆ
The Restrict โ membership, site, content and user access restrictions for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.8 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extractโฆ
4.3
CVE-2024-51460 - IBM InfoSphere Information Server information disclosure
IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information when a detailed technical error message is returned in a stack trace. This information could be used in further attacks against the system.