6.4
CVE-2024-4865 - Happy Addons for Elementor <= 3.10.8 - Authenticated (Contributor+) Stored Cross-Site Scripting viaβ¦
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β_idβ parameter in all versions up to, and including, 3.10.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-leveβ¦
0.0
CVE-2024-5089 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
9.8
CVE-2024-4264 - Remote Code Execution in berriai/litellm
A remote code execution (RCE) vulnerability exists in the berriai/litellm project due to improper control of the generation of code when using the `eval` function unsafely in the `litellm.get_secret()` method. Specifically, when the server utilizes Google KMS, untrusted data is passed to the `eval`β¦
9.8
CVE-2024-36048 - qtnetworkauth: badly seeded PRNG may result in guessable values
QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only the time to seed the PRNG, which may result in guessable values.
5.9
CVE-2024-23556 - HCL BigFix Platform is impacted by a failure to restrict SSL/TLS renegotiation
SSL/TLS Renegotiation functionality potentially leading to DoS attack vulnerability.
5.7
CVE-2024-23554 - HCL BigFix Platform is susceptible to Cross-Site Request Forgery
Cross-Site Request Forgery (CSRF) on Session Token vulnerability that could potentially lead to Remote Code Execution (RCE).
6.7
CVE-2024-23583 - HCL BigFix Platform is susceptible to insufficiently protected credentials
An attacker could potentially intercept credentials via the task manager and perform unauthorized access to the Client Deploy Tool on Windows systems.
7.3
CVE-2024-35313 -
In Tor Arti before 1.2.3, circuits sometimes incorrectly have a length of 3 (with full vanguards), aka TROVE-2024-004.
6.2
CVE-2024-35312 -
In Tor Arti before 1.2.3, STUB circuits incorrectly have a length of 2 (with lite vanguards), aka TROVE-2024-003.
5.3
CVE-2024-5069 - SourceCodester Simple Online Mens Salon Management System view_service.php sql injection
A vulnerability, which was classified as critical, has been found in SourceCodester Simple Online Mens Salon Management System 1.0. Affected by this issue is some unknown functionality of the file view_service.php. The manipulation of the argument id leads to sql injection. The attack may be launchβ¦