6.4
CVE-2024-9072 - GDPR-Extensions-com β Consent Manager <= 1.0.0 - Authenticated (Author+) Stored Cross-Site Scriptinβ¦
The GDPR-Extensions-com β Consent Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-leβ¦
6.4
CVE-2024-9457 - WP Builder <= 3.0.7 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
The WP Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.0.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inβ¦
5.4
CVE-2024-7048 - IDOR in open-webui/open-webui
In version v0.3.8 of open-webui, an improper privilege management vulnerability exists in the API endpoints GET /api/v1/documents/ and POST /rag/api/v1/doc. This vulnerability allows a lower-privileged user to access and overwrite files managed by a higher-privileged admin. By exploiting this vulneβ¦
7.5
CVE-2024-35202 -
Bitcoin Core before 25.0 allows remote attackers to cause a denial of service (blocktxn message-handling assertion and node exit) by including transactions in a blocktxn message that are not committed to in a block's merkle root. FillBlock can be called twice for one PartiallyDownloadedBlock instanβ¦
8.2
CVE-2024-6519 - Qemu: scsi: lsi53c895a: use-after-free local privilege escalation vulnerability
A use-after-free vulnerability was found in the QEMU LSI53C895A SCSI Host Bus Adapter emulation. This issue can lead to a crash or VM escape.
9.1
CVE-2024-48949 - elliptic: Missing Validation in Elliptic's EDDSA Signature Verification
The verify function in lib/elliptic/eddsa/index.js in the Elliptic package before 6.5.6 for Node.js omits "sig.S().gte(sig.eddsa.curve.n) || sig.S().isNeg()" validation.
0.0
CVE-2024-36051 -
DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2024-38365. Reason: This record is a duplicate of CVE-2024-38365. Notes: All CVE users should reference CVE-2024-38365 instead of this record. All references and descriptions in this record have been removed to prevent accidental usage.
7.8
CVE-2024-48958 - libarchive: Out-of-bounds access in libarchive's RAR file handling
execute_filter_delta in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because src can move beyond dst.
7.8
CVE-2024-48957 - libarchive: Out-of-bounds access in libarchive's archive file handling
execute_filter_audio in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because src can move beyond dst.
5.5
CVE-2024-8264 - Sensitive information in agent log file when detailed logging is enabled with Robot Schedule Enterpβ¦
Fortra's Robot Schedule Enterprise Agent prior to version 3.05 writes FTP username and password information to the agent log file when detailed logging is enabled.