6.9
CVE-2024-7797 - SourceCodester Simple Online Bidding System ajax.php sql injection
A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been classified as critical. Affected is an unknown function of the file /simple-online-bidding-system/bidding/admin/ajax.php?action=login. The manipulation of the argument username leads to sql injection. It is poโฆ
6.5
CVE-2024-43368 - Trix has a Cross-Site Scripting (XSS) vulnerability on copy & paste
The Trix editor, versions prior to 2.1.4, is vulnerable to XSS when pasting malicious code. This vulnerability is a bypass of the fix put in place for GHSA-qjqp-xr96-cj99. In pull request 1149, sanitation was added for Trix attachments with a `text/html` content type. However, Trix only checks the โฆ
5.3
CVE-2024-7794 - itsourcecode Vehicle Management System mybill.php sql injection
A vulnerability was found in itsourcecode Vehicle Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file mybill.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been โฆ
5.3
CVE-2024-7793 - SourceCodester Task Progress Tracker add-task.php cross site scripting
A vulnerability was found in SourceCodester Task Progress Tracker 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /endpoint/add-task.php. The manipulation of the argument task_name leads to cross site scripting. The attack can be launโฆ
5.3
CVE-2024-40620 - Rockwell Automation Pavilion8ยฎ Unencrypted Data Vulnerability via HTTP protocol
CVE-2024-40620 IMPACT A vulnerability exists in the affected product due to lack of encryption of sensitive information. The vulnerability results in data being sent between the Console and the Dashboard without encryption, which can be seen in the logs of proxy servers, potentially impacting the โฆ
7.7
CVE-2024-27120 - Local File Inclusion in ComfortKey before version 24.1.2
A Local File Inclusion vulnerability has been found in ComfortKey, a product of Celsius Benelux. Using this vulnerability, an unauthenticated attacker may retrieve sensitive information about the underlying system. The vulnerability has been remediated in version 24.1.2.
8.7
CVE-2024-40619 - Rockwell Automation GuardLogix/ControlLogix 5580 Controller denial-of-service Vulnerability via Malโฆ
CVE-2024-40619 IMPACT A denial-of-service vulnerability exists in the affected products. The vulnerability occurs when a malformed CIP packet is sent over the network to the device and results in a major nonrecoverable fault causing a denial-of-service.
9.8
CVE-2024-42360 - Command Injection in sequenceserver
SequenceServer lets you rapidly set up a BLAST+ server with an intuitive user interface for personal or group use. Several HTTP endpoints did not properly sanitize user input and/or query parameters. This could be exploited to inject and run unwanted shell commands. This vulnerability has been fixeโฆ
8.5
CVE-2024-7513 - Rockwell Automation FactoryTalkยฎ View Site Edition Code Execution Vulnerability via File Permissions
CVE-2024-7513 IMPACT A code execution vulnerability exists in the affected product. The vulnerability occurs due to improper default file permissions allowing any user to edit or replace files, which are executed by account with elevated permissions.
0.0
CVE-2024-7821 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.