7.6
CVE-2024-27082 - Cacti Cross-site Scripting vulnerability when managing trees
Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 are vulnerable to stored cross-site scripting, a type of cross-site scripting where malicious scripts are permanently stored on a target server and served to users who access a particular pageβ¦
5.3
CVE-2024-4819 - Campcodes Online Laundry Management System admin_class.php improper authorization
A vulnerability was found in Campcodes Online Laundry Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file admin_class.php. The manipulation of the argument type with the input 1 leads to improper authorization. It is possible to launch the attacβ¦
9.1
CVE-2024-25641 - Cacti RCE vulnerability when importing packages
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, an arbitrary file write vulnerability, exploitable through the "Package Import" feature, allows authenticated users having the "Import Templates" permission to execute arbitrary PHP code on the web serβ¦
8.8
CVE-2024-35050 -
An issue in SurveyKing v1.3.1 allows attackers to escalate privileges via re-using the session ID of a user that was deleted by an Admin.
9.1
CVE-2024-35049 -
SurveyKing v1.3.1 was discovered to keep users' sessions active after logout. Related to an incomplete fix for CVE-2022-25590.
4.3
CVE-2024-35048 -
An issue in SurveyKing v1.3.1 allows attackers to execute a session replay attack after a user changes their password.
6.9
CVE-2024-4818 - Campcodes Online Laundry Management System index.php file inclusion
A vulnerability was found in Campcodes Online Laundry Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /index.php. The manipulation of the argument page leads to file inclusion. The attack may be initiated remotely. The exploit has been disβ¦
5.3
CVE-2024-4817 - Campcodes Online Laundry Management System HTTP Request Parameter manage_user.php resource injection
A vulnerability has been found in Campcodes Online Laundry Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file manage_user.php of the component HTTP Request Parameter Handler. The manipulation of the argument id leads to improper control of resourceβ¦
5.3
CVE-2024-4816 - Ruijie RG-UAC gre_add_commit.php os command injection
A vulnerability, which was classified as critical, was found in Ruijie RG-UAC up to 20240506. This affects an unknown part of the file /view/networkConfig/GRE/gre_add_commit.php. The manipulation of the argument name/remote/local/IP leads to os command injection. It is possible to initiate the attaβ¦
7.7
CVE-2022-4967 -
strongSwan versions 5.9.2 through 5.9.5 are affected by authorization bypass through improper validation of certificate with host mismatch (CWE-297). When certificates are used to authenticate clients in TLS-based EAP methods, the IKE or EAP identity supplied by a client is not enforced to be contaβ¦