6.5
CVE-2024-33901 -
Issue in KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover some passwords stored in the .kdbx database via a memory dump. NOTE: the vendor disputes this because memory-management constraints make this unavoidable in the current design and other realistic designs.
7.9
CVE-2024-29000 - SolarWinds Platform Reflected XSS Vulnerability
The SolarWinds Platform was determined to be affected by a reflected cross-site scripting vulnerability affecting the web console. A high-privileged user and user interaction is required to exploit this vulnerability.
8.3
CVE-2023-49335 -
Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while getting file server details.
8.3
CVE-2023-49334 -
Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection while exporting a full summary report.
8.3
CVE-2023-49333 -
Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the dashboard graph feature.
8.2
CVE-2024-34949 -
SQL injection vulnerability in Likeshop before 2.5.7 allows attackers to run abitrary SQL commands via the function OrderLogic::getOrderList function, exploited at the /admin/order/lists.html endpoint.
8.3
CVE-2023-49332 -
Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while adding file shares.
8.3
CVE-2023-49331 -
Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the aggregate reports search option.
7.5
CVE-2024-34193 -
smanga 3.2.7 does not filter the file parameter at the PHP/get file flow.php interface, resulting in a path traversal vulnerability that can cause arbitrary file reading.
8
CVE-2024-35578 -
Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formSetIptv.