5.3
CVE-2024-5772 - Netentsec NS-ASG Application Security Gateway deleteiscuser.php sql injection
A vulnerability, which was classified as critical, has been found in Netentsec NS-ASG Application Security Gateway 6.3. This issue affects some unknown processing of the file /protocol/iscuser/deleteiscuser.php. The manipulation of the argument messagecontent leads to sql injection. The attack may β¦
7.5
CVE-2024-37568 -
lepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys. Unless an algorithm is specified in a jwt.decode call, HMAC verification is allowed with any asymmetric public key. (This is similar to CVE-2022-29217 and CVE-2024-33663.)
4.4
CVE-2024-37535 - vte: Denial of service via window resize escape sequence
GNOME VTE before 0.76.3 allows an attacker to cause a denial of service (memory consumption) via a window resize escape sequence, a related issue to CVE-2000-0476.
8.3
CVE-2024-37569 -
An issue was discovered on Mitel 6869i through 4.5.0.41 and 5.x through 5.0.0.1018 devices. A command injection vulnerability exists in the hostname parameter taken in by the provis.html endpoint. The provis.html endpoint performs no sanitization on the hostname parameter (sent by an authenticated β¦
8.8
CVE-2024-37570 -
On Mitel 6869i 4.5.0.41 devices, the Manual Firmware Update (upgrade.html) page does not perform sanitization on the username and path parameters (sent by an authenticated user) before appending flags to the busybox ftpget command. This leads to $() command execution.
5.3
CVE-2024-5771 - LabVantage LIMS POST Request sql injection
A vulnerability classified as critical was found in LabVantage LIMS 2017. This vulnerability affects unknown code of the file /labvantage/rc?command=page&page=SampleList&_iframename=list of the component POST Request Handler. The manipulation of the argument param1 leads to sql injection. The attacβ¦
9.8
CVE-2024-4146 - Incorrect Authorization in lunary-ai/lunary
In lunary-ai/lunary version v1.2.13, an incorrect authorization vulnerability exists that allows unauthorized users to access and manipulate projects within an organization they should not have access to. Specifically, the vulnerability is located in the `checkProjectAccess` method within the authoβ¦
8.8
CVE-2024-4680 - Insufficient Session Expiration in zenml-io/zenml
A vulnerability in zenml-io/zenml version 0.56.3 allows attackers to reuse old session credentials or session IDs due to insufficient session expiration. Specifically, the session does not expire after a password change, enabling an attacker to maintain access to a compromised account without the vβ¦
5.3
CVE-2024-22151 - WordPress Import and export users and customers plugin <= 1.24.6 - Broken Access Control vulnerabilβ¦
Missing Authorization vulnerability in Codection Import and export users and customers.This issue affects Import and export users and customers: from n/a through 1.24.6.
4.3
CVE-2024-21748 - WordPress Icegram Engage plugin <= 3.1.21 - Broken Access Control vulnerability
Missing Authorization vulnerability in Icegram.This issue affects Icegram: from n/a through 3.1.21.