Total
258583 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-40539 | 1 Codermy | 1 My-springsecurity-plus | 2024-07-12 | N/A | 9.8 CRITICAL |
| my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /api/user. | |||||
| CVE-2024-40540 | 1 Codermy | 1 My-springsecurity-plus | 2024-07-12 | N/A | 9.8 CRITICAL |
| my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /api/dept. | |||||
| CVE-2024-40541 | 1 Codermy | 1 My-springsecurity-plus | 2024-07-12 | N/A | 9.8 CRITICAL |
| my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /api/dept/build. | |||||
| CVE-2024-40542 | 1 Codermy | 1 My-springsecurity-plus | 2024-07-12 | N/A | 9.8 CRITICAL |
| my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /api/role?offset. | |||||
| CVE-2024-40543 | 1 Publiccms | 1 Publiccms | 2024-07-12 | N/A | 8.8 HIGH |
| PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/ueditor?action=catchimage. | |||||
| CVE-2024-40544 | 1 Publiccms | 1 Publiccms | 2024-07-12 | N/A | 8.8 HIGH |
| PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/#maintenance_sysTask/edit. | |||||
| CVE-2024-40545 | 1 Publiccms | 1 Publiccms | 2024-07-12 | N/A | 8.8 HIGH |
| An arbitrary file upload vulnerability in the component /admin/cmsWebFile/doUpload of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file. | |||||
| CVE-2024-40546 | 1 Publiccms | 1 Publiccms | 2024-07-12 | N/A | 8.8 HIGH |
| An arbitrary file upload vulnerability in the component /admin/cmsWebFile/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file. | |||||
| CVE-2024-40547 | 1 Publiccms | 1 Publiccms | 2024-07-12 | N/A | 6.5 MEDIUM |
| PublicCMS v4.0.202302.e was discovered to contain an arbitrary file content replacement vulnerability via the component /admin/cmsTemplate/replace. | |||||
| CVE-2024-40548 | 1 Publiccms | 1 Publiccms | 2024-07-12 | N/A | 8.8 HIGH |
| An arbitrary file upload vulnerability in the component /admin/cmsTemplate/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file. | |||||
| CVE-2024-40549 | 1 Publiccms | 1 Publiccms | 2024-07-12 | N/A | 8.8 HIGH |
| An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlace of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file. | |||||
| CVE-2024-40550 | 1 Publiccms | 1 Publiccms | 2024-07-12 | N/A | 8.8 HIGH |
| An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlaceMetaData of Public CMS v.4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file. | |||||
| CVE-2024-40551 | 1 Publiccms | 1 Publiccms | 2024-07-12 | N/A | 8.8 HIGH |
| An arbitrary file upload vulnerability in the component /admin/cmsTemplate/doUpload of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file. | |||||
| CVE-2024-40552 | 1 Publiccms | 1 Publiccms | 2024-07-12 | N/A | 8.8 HIGH |
| PublicCMS v4.0.202302.e was discovered to contain a remote commande execution (RCE) vulnerability via the cmdarray parameter at /site/ScriptComponent.java. | |||||
| CVE-2024-35707 | 1 Heateor | 1 Social Login | 2024-07-12 | N/A | 5.4 MEDIUM |
| Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Team Heateor Heateor Social Login allows Stored XSS.This issue affects Heateor Social Login: from n/a through 1.1.32. | |||||
| CVE-2024-35708 | 1 Apollo13themes | 1 Rife Free | 2024-07-12 | N/A | 5.4 MEDIUM |
| Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in apollo13themes Rife Free allows Stored XSS.This issue affects Rife Free: from n/a through 2.4.19. | |||||
| CVE-2024-39171 | 1 Phpvibe | 1 Phpvibe | 2024-07-12 | N/A | 9.8 CRITICAL |
| Directory Travel in PHPVibe v11.0.46 due to incomplete blacklist checksums and directory checks, which can lead to code execution via writing specific statements to .htaccess and code to a file with a .png suffix. | |||||
| CVE-2024-37082 | 2024-07-12 | N/A | 9.1 CRITICAL | ||
| When deploying Cloud Foundry together with the haproxy-boshrelease and using a non default configuration, it might be possible to craft HTTP requests that bypass mTLS authentication to Cloud Foundry applications. You are affected if you have route-services enabled in routing-release and have configured the haproxy-boshrelease property “ha_proxy.forwarded_client_cert” to “forward_only_if_route_service”. | |||||
| CVE-2024-5652 | 1 Docker | 1 Desktop | 2024-07-12 | N/A | 5.5 MEDIUM |
| In Docker Desktop on Windows before v4.31.0 allows a user in the docker-users group to cause a Windows Denial-of-Service through the exec-path Docker daemon config option in Windows containers mode. | |||||
| CVE-2024-6237 | 1 Redhat | 3 389 Directory Server, Directory Server, Enterprise Linux | 2024-07-12 | N/A | 6.5 MEDIUM |
| A flaw was found in the 389 Directory Server. This flaw allows an unauthenticated user to cause a systematic server crash while sending a specific extended search request, leading to a denial of service. | |||||
