4.8
CVE-2024-34349 - Sylius potentially vulnerable to Cross Site Scripting via "Name" field (Taxons, Products, Options, β¦
Sylius is an open source eCommerce platform. Prior to 1.12.16 and 1.13.1, there is a possibility to execute javascript code in the Admin panel. In order to perform an XSS attack input a script into Name field in which of the resources: Taxons, Products, Product Options or Product Variants. The codeβ¦
9.7
CVE-2024-34070 - Froxlor Vulnerable to Blind XSS Leading to Froxlor Application Compromise
Froxlor is open source server administration software. Prior to 2.1.9, a Stored Blind Cross-Site Scripting (XSS) vulnerability was identified in the Failed Login Attempts Logging Feature of the Froxlor Application. An unauthenticated User can inject malicious scripts in the loginname parameter on tβ¦
5.5
CVE-2024-30801 -
SQL Injection vulnerability in Cloud based customer service management platform v.1.0.0 allows a local attacker to execute arbitrary code via a crafted payload to Login.asp component.
5.3
CVE-2024-4720 - Campcodes Complete Web-Based School Management System approve_petty_cash.php cross site scripting
A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /model/approve_petty_cash.php. The manipulation of the argument admin_index leads to cross site scripting. The aβ¦
5.3
CVE-2024-4719 - Campcodes Complete Web-Based School Management System delete_record.php cross site scripting
A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /model/delete_record.php. The manipulation of the argument page leads to cross site scripting. The attaβ¦
7.8
CVE-2024-4044 - Deserialization of Untrusted Data Vulnerability in FlexLogger and InstrumentStudio
A deserialization of untrusted data vulnerability exists in common code used by FlexLogger and InstrumentStudio that may result in remote code execution. Successful exploitation requires an attacker to get a user to open a specially crafted project file. This vulnerability affects NI FlexLogger 2β¦
9
CVE-2024-32964 - lobe-chat `/api/proxy` endpoint Server-Side Request Forgery vulnerability
Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. Prior to 0.150.6, lobe-chat had an unauthorized Server-Side Request Forgery vulnerability in the /api/proxy endpoint. An attacker can construct malicious requests to cause Serverβ¦
6.5
CVE-2024-33774 -
A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formWlanSetup_Wizard allows remote authenticated users to trigger a denial of service (DoS) through the parameter "webpage."
6.5
CVE-2024-33773 -
A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formWlanGuestSetup allows remote authenticated users to trigger a denial of service (DoS) through the parameter "webpage."
7.5
CVE-2024-31441 - Arbitrary File Reading in DataEase
DataEase is an open source data visualization analysis tool. Due to the lack of restrictions on the connection parameters for the ClickHouse data source, it is possible to exploit certain malicious parameters to achieve arbitrary file reading. The vulnerability has been fixed in v1.18.19.