6.1
CVE-2024-37304 - NuGetGallery's Markdown Autolinks Processing Vulnerable to Cross-site Scripting
NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to its handling of autolinks in Markdown content. While the platform properly filters out JavaScript from standard links, it does not adequately sanitize autolinks. This oversight alloβ¦
9.8
CVE-2024-36265 - Apache Submarine Server Core: authorization bypass
** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Core: from 0.8.0. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative oβ¦
9.8
CVE-2024-36264 - Apache Submarine Commons Utils: default secret
** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils. If the user doesn't explicitly set `submarine.auth.default.secret`, a default value will be used. This issue affects Apache Submarine Commons Utils: from 0.8.0. As this project is retired, wβ¦
8.1
CVE-2024-36263 - Apache Submarine Server Core: SQL injection
** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Core: all versions. As this project is retired, we do not plan to release a version that fβ¦
9.3
CVE-2024-1659 - Arbitrary File Upload in MegaBIP
Arbitrary File Upload vulnerability in MegaBIP software allows attacker to upload any file to the server (including a PHP code file) without an authentication.Β This issue affects MegaBIP software versions through 5.10.
9.3
CVE-2024-1577 - Remote Code Execution in MegaBIP
Remote Code Execution vulnerability in MegaBIP software allows to execute arbitrary code on the server without requiring authentication by savingΒ crafted by the attacker PHP code to one of the website files.Β This issue affects MegaBIP software versions through 5.11.2.
9.3
CVE-2024-1576 - SQL Injection in MegaBIP
SQL Injection vulnerability in MegaBIP software allows attacker to obtain site administrator privileges, including access to the administration panel and the ability to change the administrator password.Β This issue affects MegaBIP software versions through 5.09.
8.8
CVE-2024-25949 -
Dell OS10 Networking Switches, versions10.5.6.x, 10.5.5.x, 10.5.4.x and 10.5.3.x ,contain an improper authorization vulnerability. A remote authenticated attacker could potentially exploit this vulnerability leading to escalation of privileges.
6.5
CVE-2024-5313 -
CWE-668: Exposure of the Resource Wrong Sphere vulnerability exists that exposes a SSH interface over the product network interface. This does not allow to directly exploit the product or make any unintended operation as the SSH interface access is protected by an authentication mechanism. Impacts β¦
6.5
CVE-2024-5056 -
CWE-552: Files or Directories Accessible to External Parties vulnerability exists which may prevent user to update the device firmware and prevent proper behavior of the webserver when specific files or directories are removed from the filesystem.