Total
258583 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-32493 | 2024-07-03 | N/A | 8.8 HIGH | ||
| An issue was discovered in Znuny LTS 6.5.1 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in agent is able to inject SQL in the draft form ID parameter of an AJAX request. | |||||
| CVE-2024-32492 | 2024-07-03 | N/A | 7.1 HIGH | ||
| An issue was discovered in Znuny 7.0.1 through 7.0.16 where the ticket detail view in the customer front allows the execution of external JavaScript. | |||||
| CVE-2024-32491 | 2024-07-03 | N/A | 9.8 CRITICAL | ||
| An issue was discovered in Znuny and Znuny LTS 6.0.31 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in user can upload a file (via a manipulated AJAX Request) to an arbitrary writable location by traversing paths. Arbitrary code can be executed if this location is publicly available through the web server. | |||||
| CVE-2024-32418 | 2024-07-03 | N/A | 9.8 CRITICAL | ||
| An issue in flusity CMS v2.33 allows a remote attacker to execute arbitrary code via the add_addon.php component. | |||||
| CVE-2024-32409 | 2024-07-03 | N/A | N/A | ||
| An issue in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code via a crafted script. | |||||
| CVE-2024-32407 | 2024-07-03 | N/A | 8.8 HIGH | ||
| An issue in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via a crafted payload to the Page Sandbox feature. | |||||
| CVE-2024-32406 | 2024-07-03 | N/A | 7.5 HIGH | ||
| Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via a crafted payload to the Batch-Issue Exam Tickets function. | |||||
| CVE-2024-32405 | 2024-07-03 | N/A | 2.6 LOW | ||
| Cross Site Scripting vulnerability in inducer relate before v.2024.1 allows a remote attacker to escalate privileges via a crafted payload to the Answer field of InlineMultiQuestion parameter on Exam function. | |||||
| CVE-2024-32404 | 2024-07-03 | N/A | 6.0 MEDIUM | ||
| Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1, allows remote attackers to execute arbitrary code via a crafted payload to the Markup Sandbox feature. | |||||
| CVE-2024-32399 | 2024-07-03 | N/A | 7.6 HIGH | ||
| Directory Traversal vulnerability in RaidenMAILD Mail Server v.4.9.4 and before allows a remote attacker to obtain sensitive information via the /webeditor/ component. | |||||
| CVE-2024-32394 | 2024-07-03 | N/A | N/A | ||
| An issue in ruijie.com/cn RG-RSR10-01G-T(WA)-S RSR_3.0(1)B9P2_RSR10-01G-TW-S_07150910 and RG-RSR10-01G-T(WA)-S RSR_3.0(1)B9P2_RSR10-01G-TW-S_07150910 allows a remote attacker to execute arbitrary code via a crafted HTTP request. | |||||
| CVE-2024-32392 | 2024-07-03 | N/A | 4.5 MEDIUM | ||
| Cross Site Scripting vulnerability in CmSimple v.5.15 allows a remote attacker to execute arbitrary code via the functions.php component. | |||||
| CVE-2024-32391 | 2024-07-03 | N/A | 7.3 HIGH | ||
| Cross Site Scripting vulnerability in MacCMS v.10 v.2024.1000.3000 allows a remote attacker to execute arbitrary code via a crafted payload. | |||||
| CVE-2024-32371 | 2024-07-03 | N/A | 7.5 HIGH | ||
| An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a regular user account to escalate their privileges and gain administrative access by changing the type parameter from 1 to 0. | |||||
| CVE-2024-32370 | 2024-07-03 | N/A | 9.8 CRITICAL | ||
| An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive information via a crafted payload to the id parameter in the mliSystemUsers.php component. | |||||
| CVE-2024-32369 | 2024-07-03 | N/A | 4.3 MEDIUM | ||
| SQL Injection vulnerability in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive information via a crafted payload to the start and limit parameter in the mliWhiteList.php component. | |||||
| CVE-2024-32368 | 2024-07-03 | N/A | N/A | ||
| Insecure Permission vulnerability in Agasta Sanketlife 2.0 Pocket 12-Lead ECG Monitor FW Version 3.0 allows a local attacker to cause a denial of service via the Bluetooth Low Energy (BLE) component. | |||||
| CVE-2024-32359 | 2024-07-03 | N/A | 6.9 MEDIUM | ||
| An RBAC authorization risk in Carina v0.13.0 and earlier allows local attackers to execute arbitrary code through designed commands to obtain the secrets of the entire cluster and further take over the cluster. | |||||
| CVE-2024-32355 | 2024-07-03 | N/A | 8.0 HIGH | ||
| TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'password' parameter in the setSSServer function. | |||||
| CVE-2024-32354 | 2024-07-03 | N/A | 6.0 MEDIUM | ||
| TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'timeout' parameter in the setSSServer function at /cgi-bin/cstecgi.cgi. | |||||
