5.5
CVE-2024-35384 -
An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_array_length function in the mjs.c file.
7.5
CVE-2024-35386 -
An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_do_gc function in the mjs.c file.
10
CVE-2023-3943 - Multiple buffer overflow in ZkTeco-based OEM devices
Stack-based Buffer Overflow vulnerability in ZkTeco-based OEM devices allows, in some cases, the execution of arbitrary code. Due to the lack of protection mechanisms such as stack canaries and PIE, it is possible to successfully execute code even under restrictive conditions. This issue affects β¦
6.1
CVE-2024-34071 - Open Redirect Bypass Protection
Umbraco is an ASP.NET CMS used by more than 730.000 websites. Umbraco has an endpoint that is vulnerable to open redirects. The endpoint is protected so it requires the user to be signed into backoffice before the vulnerable is exposed. This vulnerability has been patched in version(s) 8.18.14, 10.β¦
6.1
CVE-2024-35180 - OMERO.web JSONP callback vulnerability
OMERO.web provides a web based client and plugin infrastructure. There is currently no escaping or validation of the `callback` parameter that can be passed to various OMERO.web endpoints that have JSONP enabled. This vulnerability has been patched in version 5.26.0.
7.5
CVE-2023-3942 - Multiple SQLi in ZkTeco-based OEM devices
An 'SQL Injection' vulnerability, due to improper neutralization of special elements used in SQL commands, exists in ZKTeco-based OEM devices. This vulnerability allows an attacker to, in some cases, impersonate another user or perform unauthorized actions. In other instances, it enables the attackβ¦
9.8
CVE-2024-35361 -
MTab Bookmark v1.9.5 has an SQL injection vulnerability in /LinkStore/getIcon. An attacker can execute arbitrary SQL statements through this vulnerability without requiring any user rights.
6.8
CVE-2024-4420 - Denial of Service in Tink-cc
There exists a Denial of service vulnerability in Tink-cc in versions prior to 2.1.3.Β * An adversary can crash binaries using the crypto::tink::JsonKeysetReader in tink-cc by providing an input that is not an encoded JSON object, but still a valid encoded JSON element, for example a number or anβ¦
5.3
CVE-2024-3268 - YouTube Video Gallery by YouTube Showcase β Video Gallery Plugin for WordPress <= 3.3.6 - Missing Aβ¦
The YouTube Video Gallery by YouTube Showcase β Video Gallery Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the emd_form_builder_lite_submit_form function in all versions up to, and including, 3.3.6. This makes it pβ¦
6.4
CVE-2024-4619 - Elementor Website Builder β More than Just a Page Builder <= 3.21.5 - Authenticated (Contributor+) β¦
The Elementor Website Builder β More than Just a Page Builder plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the βhover_animationβ parameter in versions up to, and including, 3.21.5 due to insufficient input sanitization and output escaping. This makes it possible fβ¦