0.0
CVE-2024-45726 -
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.
0.0
CVE-2024-45727 -
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.
0.0
CVE-2024-45725 -
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.
9.3
CVE-2024-8395 - FlyCASS Cockpit Access Security System (CASS) SQL Injection
FlyCASS CASS and KCM systems did not correctly filter SQL queries, which made them vulnerable to attack by outside attackers with no authentication.
0.0
CVE-2024-8491 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
5.7
CVE-2024-42491 - A malformed Contact or Record-Route URI in an incoming SIP request can cause Asterisk to crash whenβ¦
Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.24.3, 20.9.3, and 21.4.3 of Asterisk and versions 18.9-cert12 and 20.7-cert2 of certified-asterisk, if Asterisk attempts to send a SIP request to a URI whose host portion starts with `.1` or `[.1]`, and res_resolver_unboβ¦
10
CVE-2024-7591 - Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection
Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection.This issue affects: * LoadMaster: 7.2.40.0 and above * ECS: All versions * Multi-Tenancy: 7.1.35.4 and above
7.6
CVE-2024-45401 - stripe-cli Path Traversal vulnerability
stripe-cli is a command-line tool for the payment processor Stripe. A vulnerability exists in stripe-cli starting in version 1.11.1 and prior to version 1.21.3 where a plugin package containing a manifest with a malformed plugin shortname installed using the --archive-url or --archive-path flags caβ¦
7.7
CVE-2024-45392 - SuiteCRM has wrong deletion permission checks on API delete call
SuiteCRM is an open-source customer relationship management (CRM) system. Prior to version 7.14.5 and 8.6.2, insufficient access control checks allow a threat actor to delete records via the API. Versions 7.14.5 and 8.6.2 contain a patch for the issue.
9.3
CVE-2024-24759 - MindsDB Vulnerable to Bypass of SSRF Protection with DNS Rebinding
MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat actor can bypass the server-side request forgery protection on the whole website with DNS Rebinding. The vulnerability can also lead to denial of service. Version 23.12.4.2 containsβ¦