8.7
CVE-2024-7265 - Privilege Escalation in EZD RP
Incorrect User Management vulnerability in Naukowa i Akademicka Sieฤ Komputerowa - Paลstwowy Instytut Badawczy EZD RP allows logged-in user to change the password of any user, including root user, which could lead to privilege escalation.ย This issue affects EZD RP: from 15 before 15.84, from 16 befโฆ
7.3
CVE-2024-7553 - Accessing Untrusted Directory May Allow Local Privilege Escalation
Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Windows. This may result in the application executing arbitrary behaviour determined by the contents of untrusted files. This issue affects MongoDB Serveโฆ
7.2
CVE-2024-42062 - Apache CloudStack: User Key Exposure to Domain Admins
CloudStack account-users by default use username and password based authentication for API and UI access. Account-users canย generate and register randomised API and secret keys and use them for the purpose of API-based automation and integrations.ย Due to an access permission validation issue that aโฆ
4.3
CVE-2024-42222 - Apache CloudStack: Unauthorised Network List Access
In Apache CloudStack 4.19.1.0, a regression in the network listing API allows unauthorised list access of network details for domain admin and normal user accounts. This vulnerability compromises tenant isolation, potentially leading to unauthorised access to network details, configurations and datโฆ
6.1
CVE-2024-6494 - WordPress File Upload < 4.24.8 - Unauthenticated Stored XSS
The WordPress File Upload WordPress plugin before 4.24.8 does not properly sanitize and escape certain parameters, which could allow unauthenticated users to execute stored cross-site scripting (XSS) attacks.
4.8
CVE-2024-3973 - House Manager <= 1.0.8.4 - Reflected XSS
The House Manager WordPress plugin through 1.0.8.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
9.8
CVE-2024-36130 -
An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute arbitrary commands on the underlying operating system of the appliance.
8.8
CVE-2024-36131 -
An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote attacker to execute arbitrary commands on the underlying operating system of the appliance.
7.5
CVE-2024-36132 -
Insufficient verification of authentication controls in EPMM prior to 12.1.0.1 allows a remote attacker to bypass authentication and access sensitive resources.
5.5
CVE-2024-37403 -
Ivanti Docs@Work for Android, before 2.26.0 is affected by the 'Dirty Stream' vulnerability. The application fails to properly sanitize file names, resulting in a path traversal-affiliated vulnerability. This potentially enables other malicious apps on the device to read sensitive information storeโฆ