8.7
CVE-2024-6921 - Cleartext Username and Password in NAC Telecommunication's NACPremium
Cleartext Storage of Sensitive Information vulnerability in NAC Telecommunication Systems Inc. NACPremium allows Retrieve Embedded Sensitive Data.This issue affects NACPremium: through 01082024.
4.8
CVE-2024-6920 - Stored XSS in NAC Telecommunication's NACPremium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NAC Telecommunication Systems Inc. NACPremium allows Stored XSS.This issue affects NACPremium: through 01082024.
9.3
CVE-2024-6919 - SQLi in NAC Telecommunication's NACPremium
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NAC Telecommunication Systems Inc. NACPremium allows Blind SQL Injection.This issue affects NACPremium: through 01082024.
8.7
CVE-2024-8004 - Stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator fβ¦
A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.
8.7
CVE-2024-7939 - Stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCβ¦
A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.
8.7
CVE-2024-7938 - Stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXβ¦
A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.
8.7
CVE-2024-7932 - Stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer on Release 3DEXPEβ¦
A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.
7.8
CVE-2024-38402 - Use After Free in DSP Services
Memory corruption while processing IOCTL call for getting group info.
7.8
CVE-2024-38401 - Use After Free in Qualcomm IPC
Memory corruption while processing concurrent IOCTL calls.
8.4
CVE-2024-33060 - Use After Free in DSP Service
Memory corruption when two threads try to map and unmap a single node simultaneously.