5.3
CVE-2024-9276 - TMsoft MyAuth Gateway index.php cross site scripting
A vulnerability classified as problematic has been found in TMsoft MyAuth Gateway 3. Affected is an unknown function of the file /index.php. The manipulation of the argument console/nocache/cmd leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosβ¦
5.3
CVE-2024-9275 - jeanmarc77 123solar admin_invt2.php file inclusion
A vulnerability was found in jeanmarc77 123solar up to 1.8.4.5. It has been rated as critical. This issue affects some unknown processing of the file /admin/admin_invt2.php. The manipulation of the argument PROTOCOLx leads to file inclusion. The attack may be initiated remotely. The exploit has beeβ¦
6.7
CVE-2024-9136 -
Access permission verification vulnerability in the App Multiplier module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
4.4
CVE-2024-47294 -
Access permission verification vulnerability in the input method framework module Impact: Successful exploitation of this vulnerability may affect availability.
4.7
CVE-2024-47293 -
Out-of-bounds write vulnerability in the HAL-WIFI module Impact: Successful exploitation of this vulnerability may affect availability.
6.2
CVE-2024-47292 -
Path traversal vulnerability in the Bluetooth module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
5.6
CVE-2024-47291 -
Permission vulnerability in the ActivityManagerService (AMS) module Impact: Successful exploitation of this vulnerability may affect availability.
5.5
CVE-2024-47290 -
Input validation vulnerability in the USB service module Impact: Successful exploitation of this vulnerability may affect availability.
5.3
CVE-2024-9202 - EDC DataSetResolver policy filtering missing
In Eclipse Dataspace Components versions 0.1.3 to 0.9.0, the Connector component filters which datasets (= data offers) another party can see in a requested catalog, to ensure that only authorized parties are able to view restricted offers. However, there is the possibility to request a single dataβ¦
6.1
CVE-2024-41930 -
Cross-site scripting vulnerability exists in MF Teacher Performance Management System version 6. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product.