4.8
CVE-2024-37879 -
Improper input validation in /admin/config/save in User-friendly SVN (USVN) before v1.0.12 and below allows administrators to execute arbitrary code via the fields "siteTitle", "siteIco" and "siteLogo".
7.5
CVE-2024-46649 -
eNMS up to 4.7.1 is vulnerable to Directory Traversal via download/folder.
6.5
CVE-2024-46647 -
eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via upload_files.
6.5
CVE-2024-46646 -
eNMS up to 4.7.1 is vulnerable to Directory Traversal via /download/file.
9.8
CVE-2024-46103 -
SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php.
7.5
CVE-2024-46645 -
eNMS 4.0.0 is vulnerable to Directory Traversal via get_tree_files.
9.8
CVE-2024-45489 -
Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however (because of misconfigured Firebase ACLs), it is possible to create or update a boost using another user's ID. This installs the boost in the victim's browser and โฆ
9.8
CVE-2024-46101 -
GDidees CMS <= v3.9.1 has a file upload vulnerability.
8.4
CVE-2023-47480 -
An issue in Pure Data 0.54-0 and fixed in 0.54-1 allows a local attacker to escalate privileges via the set*id () function.
9.8
CVE-2024-46652 -
Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability in the fromAdvSetMacMtuWan function.