4.7
CVE-2024-5206 - Sensitive Data Leakage in sklearn.feature_extraction.text.TfidfVectorizer in scikit-learn/scikit-leโฆ
A sensitive data leakage vulnerability was identified in scikit-learn's TfidfVectorizer, specifically in versions up to and including 1.4.1.post1, which was fixed in version 1.5.0. The vulnerability arises from the unexpected storage of all tokens present in the training data within the `stop_wordsโฆ
4.3
CVE-2024-36106 - Argo CD allows authenticated users to enumerate clusters by name
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Itโs possible for authenticated users to enumerate clusters by name by inspecting error messages. Itโs also possible to enumerate the names of projects with project-scoped clusters if you know the names of the clusters. This โฆ
8.5
CVE-2024-0912 - CCURE passwords exposed to administrators
Under certain circumstances the Microsoftยฎ Internet Information Server (IIS) used to host the CโขCURE 9000 Web Server will log Microsoft Windows credential details within logs. There is no impact to non-web service interfaces CโขCURE 9000 or prior versions
6.9
CVE-2024-5653 - Chanjet Smooth T+system keyEdit.aspx sql injection
A vulnerability, which was classified as critical, has been found in Chanjet Smooth T+system 3.5. This issue affects some unknown processing of the file /tplus/UFAQD/keyEdit.aspx. The manipulation of the argument KeyID leads to sql injection. The attack may be initiated remotely. The exploit has beโฆ
8.8
CVE-2024-36667 -
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/idcProType_deal.php?mudi=add&nohrefStr=close
5.4
CVE-2024-36668 -
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/type_deal.php?mudi=del
8.8
CVE-2024-36670 -
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/vpsClass_deal.php?mudi=del
5.4
CVE-2024-36669 -
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/type_deal.php?mudi=add.
6.7
CVE-2024-27371 -
An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_followup_get_nl_params(), there is no input validation check on hal_req->service_specific_info_len coming from userspace, which can lead to a heap overwritโฆ
6.7
CVE-2024-27373 -
An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_config_get_nl_params(), there is no input validation check on disc_attr->mesh_id_len coming from userspace, which can lead to a heap overwrite.