7.1
CVE-2024-22169 - Misconfiguration in node.js causing a code execution in WD Discovery
WD Discovery versions prior to 5.0.589 contain a misconfiguration in the Node.js environment settings that could allow code execution by utilizing the 'ELECTRON_RUN_AS_NODE'ย environment variable. Any malicious application operating with standard user permissions can exploit this vulnerability, enabโฆ
9.8
CVE-2024-7314 - anji-plus AJ-Report Authentication Bypass
anji-plus AJ-Report is affected by an authentication bypass vulnerability. A remote and unauthenticated attacker can append ";swagger-ui" to HTTP requests to bypass authentication and execute arbitrary Java on the victim server.ย Exploitation evidence was observed by the Shadowserver Foundation on 2โฆ
8.7
CVE-2024-7029 - Command Injection in AVTech AVM1203 (IP Camera)
Commands can be injected over the network and executed without authentication.
8.4
CVE-2024-41127 - Monkeytype is vulnerable to Poisoned Pipeline Execution through Code Injection in its `ci-failure-cโฆ
Monkeytype is a minimalistic and customizable typing test. Monkeytype is vulnerable to Poisoned Pipeline Execution through Code Injection in its ci-failure-comment.yml GitHub Workflow, enabling attackers to gain pull-requests write access. The ci-failure-comment.yml workflow is triggered when the Mโฆ
7.5
CVE-2024-7409 - Qemu: denial of service via improper synchronization in qemu nbd server during socket closure
A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket open as the server is taken offline.
5.3
CVE-2024-6704 - Comments โ wpDiscuz <= 7.6.21 - Unauthenticated HTML Injection
The Comments โ wpDiscuz plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 7.6.21. This is due to a lack of filtering of HTML tags in comments. This makes it possible for unauthenticated attackers to add HTML such as hyperlinks to comments when rich editing iโฆ
6.5
CVE-2024-7323 - Digiwin EasyFlow .NET - Arbitrary File Download
Digiwin EasyFlow .NET lacks proper access control for specific functionality, and the functionality do not adequately filter user input. A remote attacker with regular privilege can exploit this vulnerability to download arbitrary files from the remote server .
8.7
CVE-2024-38879 -
A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 R8.2 SP3 (All versions), Omnivise T3000 R8.2 SP4 (All versions). The affected system exposes the port of an internal application on the public network interface allowing an attacker to circuโฆ
6.9
CVE-2024-38878 -
A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 R8.2 SP3 (All versions), Omnivise T3000 R8.2 SP4 (All versions). Affected devices allow authenticated users to export diagnostics data. The corresponding API endpoint is susceptible to path โฆ
8.3
CVE-2024-38877 -
A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 Domain Controller R9.2 (All versions), Omnivise T3000 Network Intrusion Detection System (NIDS) R9.2 (All versions), Omnivise T3000 Product Data Management (PDM) R9.2 (All versions), Omnivisโฆ