8.8
CVE-2024-40474 -
A Reflected Cross Site Scripting (XSS) vulnerability was found in "edit-cate.php" in SourceCodester House Rental Management System v1.0.
5.4
CVE-2024-40473 -
A Stored Cross Site Scripting (XSS) vulnerability was found in "manage_houses.php" in SourceCodester Best House Rental Management System v1.0. It allows remote attackers to execute arbitrary code via "House_no" and "Description" parameter fields.
8.8
CVE-2024-40476 -
A Cross-Site Request Forgery (CSRF) vulnerability was found in SourceCodester Best House Rental Management System v1.0. This could lead to an attacker tricking the administrator into adding/modifying/deleting valid tenant data via a crafted HTML page, as demonstrated by a Delete Tenant action at thβ¦
7.5
CVE-2024-6893 - Journyx Unauthenticated XML External Entities Injection
The "soap_cgi.pyc" API handler allows the XML body of SOAP requests to contain references to external entities. This allows an unauthenticated attacker to read local files, perform server-side request forgery, and overwhelm the web server resources.
6.1
CVE-2024-6892 - Journyx Reflected Cross Site Scripting
Attackers can craft a malicious link that once clicked will execute arbitrary JavaScript in the context of the Journyx web application.
8.8
CVE-2024-6891 - Journyx Authenticated Remote Code Execution
Attackers with a valid username and password can exploit a python code injection vulnerability during the natural login flow.
8.8
CVE-2024-6890 - Journyx Unauthenticated Password Reset Bruteforce
Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can bruteforce the password reset and change the administrator password.
7.5
CVE-2024-6707 - Open WebUI Arbitrary File Upload + Path Traversal
Attacker controlled files can be uploaded to arbitrary locations on the web server's filesystem by abusing a path traversal vulnerability.
6.3
CVE-2024-6706 - Open WebUI Stored Cross-Site Scripting
Attackers can craft a malicious prompt that coerces the language model into executing arbitrary JavaScript in the context of the web page.
9.8
CVE-2024-41912 -
A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware flaw does not properly implement access controls.