7.5
CVE-2024-29078 -
Incorrect permission assignment for critical resource issue exists in MosP kintai kanri V4.6.6 and earlier, which may allow a remote unauthenticated attacker with access to the product to alter the product settings.
6.5
CVE-2024-28880 -
Path traversal vulnerability in MosP kintai kanri V4.6.6 and earlier allows a remote attacker who can log in to the product to obtain sensitive information of the product.
8.1
CVE-2024-36428 -
OrangeHRM 3.3.3 allows admin/viewProjects sortOrder SQL injection.
6.1
CVE-2024-34923 -
In Avocent DSR2030 Appliance firmware 03.04.00.07 before 03.07.01.23, and SVIP1020 Appliance firmware 01.06.00.03 before 01.07.00.00, there is reflected cross-site scripting (XSS).
5.9
CVE-2024-35182 - GHSL-2024-014 Meshery SQL Injection vulnerability
Meshery is an open source, cloud native manager that enables the design and management of Kubernetes-based infrastructure and applications. A SQL injection vulnerability in Meshery prior to version 0.7.22 may lead to arbitrary file write by using a SQL injection stacked queries payload, and the ATTβ¦
5.9
CVE-2024-35181 - GHSL-2024-013 Meshery SQL Injection vulnerability
Meshery is an open source, cloud native manager that enables the design and management of Kubernetes-based infrastructure and applications. A SQL injection vulnerability in Meshery prior to version 0.7.22 may lead to arbitrary file write by using a SQL injection stacked queries payload, and the ATTβ¦
8.1
CVE-2024-5154 - Cri-o: malicious container can create symlink on host
A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (β../β). This flaw allows the container to read and write to arbitrary files on the host system.
5.5
CVE-2024-36037 - Insufficient Access Control Vulnerability
Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to view the session recordings.
4.2
CVE-2024-36036 - Insufficient Access Control Vulnerability
Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to access sensitive information and modifying the agent configuration.
5.3
CVE-2024-27310 - DOS Vulnerability
Zoho ManageEngineΒ ADSelfService Plus versions belowΒ 6401 are vulnerable to the DOS attack due to the malicious LDAP input.