5.1
CVE-2024-11214 - SourceCodester Best Employee Management System profile.php unrestricted upload
A vulnerability has been found in SourceCodester Best Employee Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/profile.php. The manipulation of the argument website_image leads to unrestricted upload. The attack can be initiated remotely.β¦
5.1
CVE-2024-11213 - SourceCodester Best Employee Management System edit_role.php sql injection
A vulnerability, which was classified as critical, was found in SourceCodester Best Employee Management System 1.0. This affects an unknown part of the file /admin/edit_role.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit β¦
3.7
CVE-2024-42188 - HCL Connections is vulnerable to a broken access control vulnerability
HCL Connections is vulnerable to a broken access control vulnerability that may allow an unauthorized user to update data in certain scenarios.
5.4
CVE-2024-52505 - matrix-appservice-irc allows IRC Command injection in provisioning API
matrix-appservice-irc is a Node.js IRC bridge for the Matrix messaging protocol. The provisioning API of the matrix-appservice-irc bridge up to version 3.0.2 contains a vulnerability which can lead to arbitrary IRC command execution as the bridge IRC bot. The vulnerability has been patched in matriβ¦
8.7
CVE-2024-52302 - common-user-management Unrestricted File Upload Leading to Remote Code Execution (RCE)
common-user-management is a robust Spring Boot application featuring user management services designed to control user access dynamically. There is a critical security vulnerability in the application endpoint /api/v1/customer/profile-picture. This endpoint allows file uploads without proper validaβ¦
8.2
CVE-2024-11136 - Arbitrary file removal via path traversal in TCL Camera
The default TCL Camera application exposes a provider vulnerable to path traversal vulnerability. Malicious application can supply malicious URI path and delete arbitrary files from userβs external storage.
5.3
CVE-2024-7124 - Reflected XSS in DInGO dLibra
Improper Neutralization of Input During Web Page Generation vulnerability in DInGO dLibra softwareΒ in the parameter 'filter' in the endpoint 'indexsearch' allows a Reflected Cross-Site Scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run inβ¦
5.3
CVE-2024-11212 - SourceCodester Best Employee Management System fetch_product_details.php sql injection
A vulnerability, which was classified as critical, has been found in SourceCodester Best Employee Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/fetch_product_details.php. The manipulation of the argument barcode leads to sql injection. The attack mayβ¦
5.1
CVE-2024-11211 - EyouCMS Website Logo unrestricted upload
A vulnerability classified as critical has been found in EyouCMS up to 1.6.7. Affected is an unknown function of the component Website Logo Handler. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be uβ¦
5.3
CVE-2024-11210 - EyouCMS FilemanagerLogic.php editFile path traversal
A vulnerability was found in EyouCMS 1.51. It has been rated as critical. This issue affects the function editFile of the file application/admin/logic/FilemanagerLogic.php. The manipulation of the argument activepath leads to path traversal. The attack may be initiated remotely. The exploit has beeβ¦