7.1
CVE-2024-5921 - GlobalProtect App: Insufficient Certificate Validation Leads to Privilege Escalation
An insufficient certification validation issue in the Palo Alto Networks GlobalProtect app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating system user or an attacker on the same subnet to install malicious root certificatβ¦
9.8
CVE-2024-53676 -
A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.
5.3
CVE-2024-11820 - code-projects Crud Operation System add.php cross site scripting
A vulnerability, which was classified as problematic, has been found in code-projects Crud Operation System 1.0. This issue affects some unknown processing of the file /add.php. The manipulation of the argument saddress leads to cross site scripting. The attack may be initiated remotely. The exploiβ¦
8
CVE-2024-31976 -
EnGenius EWS356-FIR 1.1.30 and earlier devices allow a remote attacker to execute arbitrary OS commands via the Controller connectivity parameter.
4.8
CVE-2024-46055 -
OpenVidReview 1.0 is vulnerable to Cross Site Scripting (XSS) in review names.
9.8
CVE-2024-46054 -
OpenVidReview 1.0 is vulnerable to Incorrect Access Control. The /upload route is accessible without authentication, allowing any user to upload files.
6.8
CVE-2024-51228 -
An issue in TOTOLINK-CX-A3002RU V1.0.4-B20171106.1512 and TOTOLINK-CX-N150RT V2.1.6-B20171121.1002 and TOTOLINK-CX-N300RT V2.1.6-B20170724.1420 and TOTOLINK-CX-N300RT V2.1.8-B20171113.1408 and TOTOLINK-CX-N300RT V2.1.8-B20191010.1107 and TOTOLINK-CX-N302RE V2.0.2-B20170511.1523 allows a remote attaβ¦
8
CVE-2024-52951 -
Stored Cross-Site Scripting in the Access Request History in Omada Identity before version 15 update 1 allows an authenticated attacker to execute arbitrary code in the browser of a victim via a specially crafted link or by viewing a manipulated Access Request History
4.2
CVE-2024-37816 -
Quectel EC25-EUX EC25EUXGAR08A05M1G was discovered to contain a stack overflow.
4.8
CVE-2024-53635 -
A Reflected Cross Site Scripting (XSS) vulnerability was found in /covid-tms/patient-search-report.php in PHPGurukul COVID 19 Testing Management System v1.0, which allows remote attackers to execute arbitrary code via the searchdata POST request parameter.