5.3
CVE-2024-8706 - JFinalCMS com.cms.util.TemplateUtils update path traversal
A vulnerability was found in JFinalCMS up to 20240903. It has been classified as problematic. This affects the function update of the file /admin/template/update of the component com.cms.util.TemplateUtils. The manipulation of the argument fileName leads to path traversal. It is possible to initiatโฆ
8.5
CVE-2024-28981 - Hitachi Vantara Pentaho Data Integration & Analytics - Insufficiently Protected Credentials
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when searching metadata injectable fields.
5.4
CVE-2024-7890 - Local privilege escalation allows a low-privileged user to gain SYSTEM privileges
Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
5.3
CVE-2024-8705 - Shandong Star Measurement and Control Equipment Heating Network Wireless Monitoring System UCCGSrv.โฆ
A vulnerability was found in Shandong Star Measurement and Control Equipment Heating Network Wireless Monitoring System 5.6.2 and classified as critical. Affected by this issue is the function GetDataKindByType of the file /DataSrvs/UCCGSrv.asmx. The manipulation leads to sql injection. The attack โฆ
7
CVE-2024-7889 - Local privilege escalation allows a low-privileged user to gain SYSTEM privileges
Local privilege escalation allows a low-privileged user to gain SYSTEM privilegesย inย Citrix Workspace app for Windows
5.1
CVE-2024-8694 - JFinalCMS com.cms.controller.admin.TemplateController update path traversal
A vulnerability, which was classified as problematic, was found in JFinalCMS up to 20240903. This affects the function update of the file /admin/template/update of the component com.cms.controller.admin.TemplateController. The manipulation of the argument fileName leads to path traversal. It is posโฆ
5.1
CVE-2024-8693 - Kaon CG3000 dhcpcd Command cross site scripting
A vulnerability, which was classified as problematic, has been found in Kaon CG3000 1.01.43. Affected by this issue is some unknown functionality of the component dhcpcd Command Handler. The manipulation of the argument -h with the input <script>alert('XSS')</script> leads to cross site scripting. โฆ
6.9
CVE-2024-8692 - TDuckCloud TDuckPro password recovery
A vulnerability classified as critical was found in TDuckCloud TDuckPro up to 6.3. Affected by this vulnerability is an unknown functionality. The manipulation leads to weak password recovery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The venโฆ
5.3
CVE-2024-8691 - PAN-OS: User Impersonation in GlobalProtect Portal
A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated GlobalProtect user to impersonate another GlobalProtect user. Active GlobalProtect users impersonated by an attacker who is exploiting this vulnerability are disconnected from GlobalPโฆ
5.6
CVE-2024-8690 - Cortex XDR Agent: Local Windows Administrator Can Disable the Agent
A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows administrator privileges to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.