8.8
CVE-2024-25131 - Openshift-dedicated: must-gather-operator: yaml template injection leads to privilege escalation
A flaw was found in the MustGather.managed.openshift.io Custom Defined Resource (CRD) of OpenShift Dedicated. A non-privileged user on the cluster can create a MustGather object with a specially crafted file and set the most privileged service account to run the job. This can allow a standard develβ¦
9.6
CVE-2023-51219 -
A deep link validation issue in KakaoTalk 10.4.3 allowed a remote adversary to direct users to run any attacker-controlled JavaScript within a WebView. The impact was further escalated by triggering another WebView that leaked its access token in a HTTP request header. Ultimately, this access tokenβ¦
9.1
CVE-2024-34987 -
A SQL Injection vulnerability exists in the `ofrs/admin/index.php` script of PHPGurukul Online Fire Reporting System 1.2. The vulnerability allows attackers to bypass authentication and gain unauthorized access by injecting SQL commands into the username input field during the login process.
5.3
CVE-2024-5588 - itsourcecode Learning Management System processscore.php sql injection
A vulnerability was found in itsourcecode Learning Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file processscore.php. The manipulation of the argument LessonID leads to sql injection. The attack can be launched remotely.β¦
6.1
CVE-2024-36392 - MileSight DeviceHub - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-sβ¦
MileSight DeviceHub -Β CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
9.1
CVE-2024-36391 - MileSight DeviceHub - CWE-320: Key Management Errors
MileSight DeviceHub -Β CWE-320: Key Management Errors may allow Authentication Bypass and Man-In-The-Middle Traffic
7.5
CVE-2024-36390 - MileSight DeviceHub - CWE-20 Improper Input Validation
MileSight DeviceHub -Β CWE-20 Improper Input Validation may allow Denial of Service
9.8
CVE-2024-36389 - MileSight DeviceHub - CWE-330 Use of Insufficiently Random Values
MileSight DeviceHub - CWE-330 Use of Insufficiently Random Values may allow Authentication Bypass
10
CVE-2024-36388 - MileSight DeviceHub - CWE-305 Missing Authentication for Critical Function
MileSight DeviceHub - CWE-305 Missing Authentication for Critical Function
9.8
CVE-2024-27776 - MileSight DeviceHub - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traβ¦
MileSight DeviceHub - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') may allow Unauthenticated RCE