9.8
CVE-2024-48411 -
itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to SQL Injection (SQLI) via a crafted payload to the val-email parameter in forget_password.php.
4.8
CVE-2024-48948 - elliptic: ECDSA signature verification error may reject legitimate transactions
The Elliptic package 6.5.7 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if the hash contains at least four leading 0 bytes and when the order of the elliptic curve's base point is smaller than the hash, because of an _truncateToN anomaly. This leads to vaโฆ
6.5
CVE-2024-48714 -
In TP-Link TL-WDR7660 v1.0, the guestRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.
7.2
CVE-2024-9548 - Slimstat Analytics <= 5.2.6 - Unauthenticated Stored Cross-Site Scripting
The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the resource parameter in all versions up to, and including, 5.2.6 due to insufficient input sanitization and output escaping when logging visitor requests. This makes it possible for unauthenticated attackโฆ
5.3
CVE-2024-9546 - WPIDE <= 3.4.9 - Unauthenticated Full Path Dislcosure
The WPIDE โ File Manager & Code Editor plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.4.9. This is due to the plugin utilizing the PHP-Parser library, which outputs parser rebuild command execution results. This makes it possible for unauthenticatโฆ
2.5
CVE-2024-30117 - HCL BigFix Platform is affected by a DLL Hijack vulnerability
A dynamic search for a prerequisite library could allow the possibility for an attacker to replace the correct file under some circumstances.
4.9
CVE-2024-9953 - Potential DoS Vulnerability in CERT VINCE Software Before Version 3.0.8
A potential denial-of-service (DoS) vulnerability exists in CERT VINCE software versions prior to 3.0.8. An authenticated administrative user can inject an arbitrary pickle object into a userโs profile, which may lead to a DoS condition when the profile is accessed. While the Django server restrictโฆ
8.7
CVE-2024-6207 -
CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html ย and send a specially crafted CIP message to the device. If exploited, a threat actor could help prevent access to the legitimate user and end connections to connected devices including thโฆ
5.8
CVE-2024-48911 - OpenCanary Executes Commands From Potentially Writable Config File
OpenCanary, a multi-protocol network honeypot, directly executed commands taken from its config file. Prior to version 0.9.4, where the config file is stored in an unprivileged user directory but the daemon is executed by root, itโs possible for the unprivileged user to change the config file and eโฆ
2
CVE-2024-48909 - SpiceDB calls to LookupResources using LookupResources2 with caveats may return context is missing โฆ
SpiceDB is an open source database for scalably storing and querying fine-grained authorization data. Starting in version 1.35.0 and prior to version 1.37.1, clients that have enabled `LookupResources2` and have caveats in the evaluation path for their requests can return a permissionship of `CONDIโฆ