5.4
CVE-2024-10146 - Simple File List < 6.1.13 - Reflected Cross-Site Scripting
The Simple File List WordPress plugin before 6.1.13 does not sanitise and escape a generated URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against admins.
6.7
CVE-2023-34049 - Salt security advisory release - 2023-OCT-27
The Salt-SSH pre-flight option copies the script to the target at a predictable path, which allows an attacker to force Salt-SSH to run their script. If an attacker has access to the target VM and knows the path to the pre-flight script before it runs they can ensure Salt-SSH runs their script withβ¦
7.1
CVE-2024-5082 - Nexus Repository 2 - Remote Code Execution
A Remote Code Execution vulnerability has been discovered in Sonatype Nexus Repository 2.Β This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1.
5.1
CVE-2024-5083 - Nexus Repository 2 - Stored XSS
A storedΒ Cross-site Scripting vulnerability has been discovered in Sonatype Nexus Repository 2 This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1.
6.1
CVE-2024-40579 -
Cross Site Scripting vulnerability in Virtuozzo Hybrid Server for WHMCS Open Source v.1.7.1 allows a remote attacker to obtain sensitive information via modification of the hostname parameter.
8.8
CVE-2024-41209 -
A heap-based buffer overflow in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Denial of Service (DoS) and Code Execution via a crafted MOV video file.
6.5
CVE-2024-41217 -
A heap-based buffer overflow in tsMuxer version nightly-2024-05-10-02-00-45 allows attackers to cause Denial of Service (DoS) via a crafted MKV video file.
9.8
CVE-2024-31695 -
A misconfiguration in the fingerprint authentication mechanism of Binance: BTC, Crypto and NFTS v2.85.4, allows attackers to bypass authentication when adding a new fingerprint.
4.9
CVE-2024-11217 - Oauth-server-container: oauth-server-container logs client secret in debug level
A vulnerability was found in the OAuth-server. OAuth-server logs the OAuth2 client secret when the logLevel is Debug higher for OIDC/GitHub/GitLab/Google IDPs login options.
3.5
CVE-2024-50826 -
A SQL Injection vulnerability was found in /admin/add_content.php in kashipara E-learning Management System Project 1.0 via the title and content parameters.