9.8
CVE-2024-33957 - SQL injection in Janobe E-Negosyo System
SQL injection vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in 'id' in '/admin/orders/controller.php' parameter
7.1
CVE-2024-33978 - Cross-site Scripting in Janobe E-Negosyo System
Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session cookie details via 'category' parameter in '/index.php'.
6.4
CVE-2024-7317 - Folders β Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager <= 3.0.3 -β¦
The Folders β Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.0.3 due to insufficient input sanitization and output escaping. This makes it pβ¦
7.1
CVE-2024-33977 - Cross-site Scripting in Janobe E-Negosyo System
Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session cookie details via 'view' parameter in /admin/orders/index.php'.
7.1
CVE-2024-33976 - Cross-site Scripting in Janobe E-Negosyo System
Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted JavaScript payload to an authenticated user and partially take over their browser session viaΒ 'id' parameter in '/admin/user/index.php'.
7.1
CVE-2024-33975 - Cross-site Scripting in Janobe E-Negosyo System
Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted JavaScript payload to an authenticated user and partially take over their browser session viaΒ 'view' parameter in '/admin/products/index.phβ¦
7.5
CVE-2024-41995 -
Initialization of a resource with an insecure default vulnerability exists in JavaTM Platform Ver.12.89 and earlier. If this vulnerability is exploited, the product may be affected by some known TLS1.0 and TLS1.1 vulnerabilities. As for the specific products/models/versions of MFPs and printers thaβ¦
8.3
CVE-2024-6203 - HaloITSM - Password Reset Poisoning
HaloITSM versions up to 2.146.1 are affected by a Password Reset Poisoning vulnerability. Poisoned password reset links can be sent to existing HaloITSM users (given their email address is known). When these poisoned links get accessed (e.g. manually by the victim or automatically by an email clienβ¦
9.8
CVE-2024-6202 - HaloITSM - SAML XML Signature Wrapping (XSW)
HaloITSM versions up to 2.146.1 are affected by a SAML XML Signature Wrapping (XSW) vulnerability. When having a SAML integration configured, anonymous actors could impersonate arbitrary HaloITSM users by just knowing their email address. HaloITSM versions past 2.146.1 (and patches starting from 2.β¦
6.9
CVE-2024-7055 - FFmpeg pnmdec.c pnm_decode_frame heap-based overflow
A vulnerability was found in FFmpeg up to 7.0.1. It has been classified as critical. This affects the function pnm_decode_frame in the library /libavcodec/pnmdec.c. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed tβ¦