7.5
CVE-2024-47220 - WEBrick: HTTP request smuggling
An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., "GET /admin HTTP/1.1\r\n" inside of a "POST /user HTTP/1.1\r\n" request. NOTE: the supplier's position is "Webrick β¦
7.5
CVE-2024-47221 -
CheckUser in ScadaServerEngine/MainLogic.cs in Rapid SCADA through 5.8.4 allows an empty password.
9.8
CVE-2024-47218 -
An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows bypassing authentication.
5.4
CVE-2024-47226 -
A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. An authenticated user can inject arbitrary JavaScript or HTML into the "Top banner" field. NOTE: Multiple third parties β¦
2.3
CVE-2024-9075 - Stirling-Tools Stirling-PDF Markdown-to-PDF cross site scripting
A vulnerability was found in Stirling-Tools Stirling-PDF up to 0.28.3. It has been declared as problematic. This vulnerability affects unknown code of the component Markdown-to-PDF. The manipulation leads to cross site scripting. The attack can be initiated remotely. The complexity of an attack is β¦
8.8
CVE-2024-42323 - Apache HertzBeat: RCE by snakeYaml deser load malicious xml
SnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating).Β This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat (incubating): before 1.6.0. Users are recommended to upgrade to version 1.6.0, which fixes the issue.
4.4
CVE-2024-8680 - MailChimp for Wordpress <= 4.9.16 - Authenticated (Administrator+) Stored Cross-Site Scripting
The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.9.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-levβ¦
6.3
CVE-2024-9048 - y_project RuoYi Backend User Import SysUserServiceImpl.java SysUserServiceImpl cross site scripting
A vulnerability was found in y_project RuoYi up to 4.7.9. It has been declared as problematic. Affected by this vulnerability is the function SysUserServiceImpl of the file ruoyi-system/src/main/java/com/ruoyi/system/service/impl/SysUserServiceImpl.java of the component Backend User Import. The manβ¦
6
CVE-2024-6787 - MXview One Series vulnerable to Time-of-check Time-of-use (TOCTOU) Race Condition
This vulnerability occurs when an attacker exploits a race condition between the time a file is checked and the time it is used (TOCTOU). By exploiting this race condition, an attacker can write arbitrary files to the system. This could allow the attacker to execute malicious code and potentially cβ¦
6
CVE-2024-6786 - MXview One Series vulnerable to Path Traversal
The vulnerability allows an attacker to craft MQTT messages that include relative path traversal sequences, enabling them to read arbitrary files on the system. This could lead to the disclosure of sensitive information, such as configuration files and JWT signing secrets.