5.3
CVE-2024-38809 - org.springframework:spring-web: Spring Framework DoS via conditional HTTP request
Applications that parse ETags from "If-Match" or "If-None-Match" request headers are vulnerable to DoS attack. Users of affected versions should upgrade to the corresponding fixed version. Users of older, unsupported versions could enforce a size limit on "If-Match" and "If-None-Match" headers, eβ¦
9.8
CVE-2024-42507 - Unauthenticated Command Injection Vulnerabilities in the CLI Service Accessed by the PAPI Protocol
Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities results in the aβ¦
9.8
CVE-2024-42506 - Unauthenticated Command Injection Vulnerabilities in the CLI Service Accessed by the PAPI Protocol
Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities results in the aβ¦
9.8
CVE-2024-42505 - Unauthenticated Command Injection Vulnerabilities in the CLI Service Accessed by the PAPI Protocol
Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities results in the aβ¦
3.8
CVE-2024-45599 - TCC Bypass in Cursor's macOS Application
Cursor is an artificial intelligence code editor. Prior to version 0.41.0, if a user on macOS has granted Cursor access to the camera or microphone, any program that is run on the machine is able to access the camera or the microphone without explicitly being granted access, through a DyLib Injectiβ¦
5.8
CVE-2024-8067 - Unicode "best fit" argument injection
In versions of Helix Core prior to 2024.1 Patch 2 (2024.1/2655224) a Windows ANSI API Unicode "best fit" argument injection was identified.
6.9
CVE-2024-8877 - SQL Injection
Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204. It is only limited to the SQLite database of measurement data.This issue affects Netman 204: through 4.05.
10
CVE-2024-8878 - Unauthenticated Password Reset
The password recovery mechanism for the forgotten password in Riello Netman 204 allows an attacker to reset the admin password and take over control of the device.This issue affects Netman 204: through 4.05.
9.6
CVE-2024-9148 - Flowise Stored Cross-Site Scripting
Flowise < 2.1.1 suffers from a Stored Cross-Site vulnerability due to a lack of input sanitization in Flowise Chat Embed < 2.0.0.
6.3
CVE-2024-8942 - Cross-site Scripting vulnerability on Scriptcase
Vulnerability in Scriptcase version 9.4.019 that consists of a Cross-Site Scripting (XSS), due to the lack of input validation, affecting the βid_form_msg_titleβ parameter, among others. This vulnerability could allow a remote user to send a specially crafted URL to a victim and retrieve their credβ¦