5.5
CVE-2024-41200 -
A segmentation fault in KMPlayer v4.2.2.65 allows attackers to cause a Denial of Service (DoS) via a crafted AVI file.
6
CVE-2023-31355 - linux-firmware: hw:amd: Improper Restriction of Write Operations in SNP Firmware
Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to overwrite a guest's UMC seed potentially allowing reading of memory from a decommissioned guest.
6.9
CVE-2024-7461 - ForIP Tecnologia Administração PABX monitcallcenter authMonitCallcenter sql injection
A vulnerability was found in ForIP Tecnologia Administração PABX 1.x. It has been rated as critical. Affected by this issue is some unknown functionality of the file /authMonitCallcenter of the component monitcallcenter. The manipulation of the argument user leads to sql injection. The attack may b…
6.9
CVE-2024-7460 - OSWAPP Warehouse Inventory System change_password.php cross-site request forgery
A vulnerability was found in OSWAPP Warehouse Inventory System 1.0/2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /change_password.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The ex…
6.9
CVE-2024-7459 - OSWAPP Warehouse Inventory System edit_account.php cross-site request forgery
A vulnerability was found in OSWAPP Warehouse Inventory System 1.0/2.0. It has been classified as problematic. Affected is an unknown function of the file /edit_account.php. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disc…
5.1
CVE-2024-7458 - elunez eladmin Database Management/Deployment Management upload path traversal
A vulnerability was found in elunez eladmin up to 2.7 and classified as critical. This issue affects some unknown processing of the file /api/deploy/upload /api/database/upload of the component Database Management/Deployment Management. The manipulation of the argument file leads to path traversal:…
6.7
CVE-2024-35143 - IBM Planning Analytics Local missing authentication
IBM Planning Analytics Local 2.0 and 2.1 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it is configured to allow connections without password authentication. A remote attacker can gain unauthorized access to the database. IBM X-For…
5.3
CVE-2024-7455 - itsourcecode Tailoring Management System partedit.php sql injection
A vulnerability, which was classified as critical, was found in itsourcecode Tailoring Management System 1.0. This affects an unknown part of the file partedit.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been discl…
5.3
CVE-2024-7454 - SourceCodester Clinics Patient Management System patients.php patient_name sql injection
A vulnerability, which was classified as critical, has been found in SourceCodester Clinics Patient Management System 1.0. Affected by this issue is the function patient_name of the file patients.php. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been…
5.1
CVE-2024-7453 - FastAdmin Attachment Management Section 4 cross site scripting
A vulnerability was found in FastAdmin 1.5.0.20240328. It has been declared as problematic. This vulnerability affects unknown code of the file /[admins_url].php/general/attachment/edit/ids/4?dialog=1 of the component Attachment Management Section. The manipulation of the argument row[url]/row[imag…