3.7
CVE-2024-42188 - HCL Connections is vulnerable to a broken access control vulnerability
HCL Connections is vulnerable to a broken access control vulnerability that may allow an unauthorized user to update data in certain scenarios.
5.4
CVE-2024-52505 - matrix-appservice-irc allows IRC Command injection in provisioning API
matrix-appservice-irc is a Node.js IRC bridge for the Matrix messaging protocol. The provisioning API of the matrix-appservice-irc bridge up to version 3.0.2 contains a vulnerability which can lead to arbitrary IRC command execution as the bridge IRC bot. The vulnerability has been patched in matriโฆ
8.7
CVE-2024-52302 - common-user-management Unrestricted File Upload Leading to Remote Code Execution (RCE)
common-user-management is a robust Spring Boot application featuring user management services designed to control user access dynamically. There is a critical security vulnerability in the application endpoint /api/v1/customer/profile-picture. This endpoint allows file uploads without proper validaโฆ
8.2
CVE-2024-11136 - Arbitrary file removal via path traversal in TCL Camera
The default TCL Camera application exposes a provider vulnerable to path traversal vulnerability. Malicious application can supply malicious URI path and delete arbitrary files from userโs external storage.
5.3
CVE-2024-7124 - Reflected XSS in DInGO dLibra
Improper Neutralization of Input During Web Page Generation vulnerability in DInGO dLibra softwareย in the parameter 'filter' in the endpoint 'indexsearch' allows a Reflected Cross-Site Scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run inโฆ
5.3
CVE-2024-11212 - SourceCodester Best Employee Management System fetch_product_details.php sql injection
A vulnerability, which was classified as critical, has been found in SourceCodester Best Employee Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/fetch_product_details.php. The manipulation of the argument barcode leads to sql injection. The attack mayโฆ
5.1
CVE-2024-11211 - EyouCMS Website Logo unrestricted upload
A vulnerability classified as critical has been found in EyouCMS up to 1.6.7. Affected is an unknown function of the component Website Logo Handler. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be uโฆ
5.3
CVE-2024-11210 - EyouCMS FilemanagerLogic.php editFile path traversal
A vulnerability was found in EyouCMS 1.51. It has been rated as critical. This issue affects the function editFile of the file application/admin/logic/FilemanagerLogic.php. The manipulation of the argument activepath leads to path traversal. The attack may be initiated remotely. The exploit has beeโฆ
8.8
CVE-2024-10962 - Migration, Backup, Staging โ WPvivid <= 0.9.107 - Unauthenticated PHP Object Injection
The Migration, Backup, Staging โ WPvivid plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.9.107 via deserialization of untrusted input in the 'replace_row_data' and 'replace_serialize_data' functions. This makes it possible for unauthenticated attacโฆ
6.5
CVE-2024-11215 - Path traversal vulnerability in EasyPHP
Absolute path traversal (incorrect restriction of a path to a restricted directory) vulnerability in the EasyPHP web server, affecting version 14.1. This vulnerability could allow remote users to bypass SecurityManager restrictions and retrieve any file stored on the server by setting only consecutโฆ