6.4
CVE-2024-37900 - XWiki Platform vulnerable to Cross-site Scripting through attachment filename in uploader
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When uploading an attachment with a malicious filename, malicious JavaScript code could be executed. This requires a social engineering attack to get the victim into uploading a file with a maliβ¦
4.3
CVE-2024-37898 - XWiki Platform vulnerable to document deletion and overwrite from edit
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When a user has view but not edit right on a page in XWiki, that user can delete the page and replace it by a page with new content without having delete right. The previous version of the page β¦
8.8
CVE-2024-7340 - W&B Weave server remote arbitrary file leak and privilege escalation
The Weave server API allows remote users to fetch files from a specific directory, but due to a lack of input validation, it is possible to traverse and leak arbitrary files remotely. In various common scenarios, this allows a low-privileged user to assume the role of the server admin.
3.3
CVE-2024-37135 -
DM5500 5.16.0.0, contains an information disclosure vulnerability. A local attacker with high privileges could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application β¦
3.3
CVE-2024-31203 -
A βCWE-121: Stack-based Buffer Overflowβ in the wd210std.dll dynamic library packaged with the ThermoscanIP installer allows a local attacker to possibly trigger a Denial-of-Service (DoS) condition on the target component.
7.8
CVE-2024-31202 -
A βCWE-732: Incorrect Permission Assignment for Critical Resourceβ in the ThermoscanIP installation folder allows a local attacker to perform a Local Privilege Escalation.
6.5
CVE-2024-31201 -
A βCWE-428: Unquoted Search Path or Elementβ affects the ThermoscanIP_Scrutation service. Such misconfiguration could be abused in scenarios where incorrect permissions were assigned to the C:\ path to attempt a privilege escalation on the local machine.
4.2
CVE-2024-31200 -
A βCWE-201: Insertion of Sensitive Information Into Sent Dataβ affecting the administrative account allows an attacker with physical access to the machine to retrieve the password in cleartext when an administrative session is open in the browser.
8.8
CVE-2024-31199 -
A βCWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')β allows malicious users to permanently inject arbitrary Javascript code.
8.3
CVE-2024-3083 -
A βCWE-352: Cross-Site Request Forgery (CSRF)β can be exploited by remote attackers to perform state-changing operations with administrative privileges by luring authenticated victims into visiting a malicious web page.