7.7
CVE-2024-5585 - Command injection via array-ish $command parameter of proc_open() (bypass CVE-2024-1874 fix)
In PHP versionsย 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, the fix forย CVE-2024-1874 does not work if the command name includes trailing spaces. Original issue:ย when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed commanโฆ
8.4
CVE-2023-37539 - HCL Domino Catalog template is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability
The Domino Catalog template is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. An attacker with the ability to edit documents in the catalog application/database created from this template can embed a cross site scripting attack. The attack would be activated by an end user clickโฆ
4.7
CVE-2024-36775 -
A cross-site scripting (XSS) vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the About Me parameter in the Edit Profile page.
7.2
CVE-2024-36774 -
An arbitrary file upload vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary code via uploading a crafted PHP file.
5.6
CVE-2024-4013 - Failure to update BT Mesh Replay Protection List
A bug exists in the API, mesh_node_power_off(), which fails to copy the contents of the Replay Protection List (RPL) from RAM to NVM before powering down, resulting in the ability to replay unsaved messages. Note that as of June 2024, the Gecko SDK was renamed to the Simplicity SDK, and the versioโฆ
7.5
CVE-2023-51847 -
An issue in obgm and Libcoap v.a3ed466 allows a remote attacker to cause a denial of service via thecoap_context_t function in the src/coap_threadsafe.c:297:3 component.
5.5
CVE-2024-22525 -
dnspod-sr 0dfbd37 contains a SEGV.
5.5
CVE-2024-22524 -
dnspod-sr 0dfbd37 is vulnerable to buffer overflow.
7.5
CVE-2024-24199 -
smartdns commit 54b4dc was discovered to contain a misaligned address at smartdns/src/dns.c.
7.5
CVE-2024-24198 -
smartdns commit 54b4dc was discovered to contain a misaligned address at smartdns/src/util.c.