8.4
CVE-2024-36474 - libgsf: Compound Document Binary File Directory integer overflow vulnerability
An integer overflow vulnerability exists in the Compound Document Binary File format parser of the GNOME Project G Structured File Library (libgsf) version v1.14.52. A specially crafted file can result in an integer overflow when processing the directory from the file that allows for an out-of-bounβ¦
7.5
CVE-2024-41163 -
A directory traversal vulnerability exists in the archive functionality of Veertu Anka Build 1.42.0. A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.
7.8
CVE-2024-39755 -
A privilege escalation vulnerability exists in the node update functionality of Veertu Anka Build 1.42.0. A specially crafted PKG file can lead to execute priviledged operation. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.
7.5
CVE-2024-41922 -
A directory traversal vulnerability exists in the log files download functionality of Veertu Anka Build 1.42.0. A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.
5.3
CVE-2024-47211 - openstack-ironic: Lack of checksum validation on images
In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming.
6.9
CVE-2024-9460 - Codezips Online Shopping Portal index.php sql injection
A vulnerability was found in Codezips Online Shopping Portal 1.0. It has been classified as critical. Affected is an unknown function of the file index.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosedβ¦
7.5
CVE-2024-47614 - async-graphql vulnerable to Directive Overload
async-graphql is a GraphQL server library implemented in Rust. async-graphql before 7.0.10 does not limit the number of directives for a field. This can lead to Service Disruption, Resource Exhaustion, and User Experience Degradation. This vulnerability is fixed in 7.0.10.
6.1
CVE-2024-47617 - Reflected XSS Vulnerability in Sulu Media Bundle
Sulu is a PHP content management system. This vulnerability allows an attacker to inject arbitrary HTML/JavaScript code through the media download URL in Sulu CMS. It affects the SuluMediaBundle component. The vulnerability is a Reflected Cross-Site Scripting (XSS) issue, which could potentially alβ¦
7.5
CVE-2024-5803 - Local privelage escalation via COM hijacking
The AVGUI.exe of AVG/Avast Antivirus before versions before 24.1 can allow a local attacker to escalate privileges via an COM hijack in a time-of-check to time-of-use (TOCTOU) when self protection is disabled.
5.1
CVE-2024-47618 - Sulu vulnerable to XSS via uploaded SVG
Sulu is a PHP content management system. Sulu is vulnerable against XSS whereas a low privileged user with access to the βMediaβ section can upload an SVG file with a malicious payload. Once uploaded and accessed, the malicious javascript will be executed on the victimsβ (other users including admiβ¦