7.5
CVE-2024-41700 - Barix β CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Barix β CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
6.5
CVE-2024-25009 - Ericsson Packet Core Controller (PCC) - Improper Input Validation Vulnerability
Ericsson Packet Core Controller (PCC) contains a vulnerability in Access and Mobility Management Function (AMF) where improper input validation can lead to denial of service which may result in service degradation.
4.4
CVE-2024-41699 - Priority β CWE-552: Files or Directories Accessible to External Parties
Priority β CWE-552: Files or Directories Accessible to External Parties
4.3
CVE-2024-41698 - Priority β CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Priority β CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
6.1
CVE-2024-41697 - Priority β CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
Priority -Β CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
6.4
CVE-2024-7054 - Popup Maker <= 1.19.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
The Popup Maker β Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the βclose_textβ parameter in all versions up to, and including, 1.19.0 due to insufficient input sanitization and output escapinβ¦
8.0
CVE-2024-21689 -
This High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689Β was introduced in versions 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0, and 9.6.0 of Bamboo Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.6, allows an authenticated attacker to exeβ¦
5.2
CVE-2024-28829 - Privilege escalation in mk_informix plugin
Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk 2.3.0p12, 2.2.0p32, 2.1.0p47 and 2.0.0 (EOL) allows local users to escalate privileges.
9.8
CVE-2024-43202 - Apache DolphinScheduler: Remote Code Execution Vulnerability
Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.2. We recommend users to upgrade Apache DolphinScheduler to version 3.2.2, which fixes the issue.
9.8
CVE-2024-6847 - SmartSearch WP <= 2.4.4 - Unauthenticated SQLi
The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when submitting messages to the chatbot.