Total
258583 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-31845 | 2024-07-03 | N/A | 5.3 MEDIUM | ||
| An issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly neutralizes output that is written to logs. The web application writes logs using a GET query string parameter. This parameter can be modified by an attacker, so that every action he performs is attributed to a different user. This can be exploited without authentication. | |||||
| CVE-2024-31843 | 2024-07-03 | N/A | 4.1 MEDIUM | ||
| An issue was discovered in Italtel Embrace 1.6.4. The Web application does not properly check the parameters sent as input before they are processed on the server side. This allows authenticated users to execute commands on the Operating System. | |||||
| CVE-2024-31841 | 2024-07-03 | N/A | 7.5 HIGH | ||
| An issue was discovered in Italtel Embrace 1.6.4. The web server fails to sanitize input data, allowing remote unauthenticated attackers to read arbitrary files on the filesystem. | |||||
| CVE-2024-31828 | 2024-07-03 | N/A | 6.1 MEDIUM | ||
| Cross Site Scripting vulnerability in Lavalite CMS v.10.1.0 allows attackers to execute arbitrary code and obtain sensitive information via a crafted payload to the URL. | |||||
| CVE-2024-31823 | 2024-07-03 | N/A | 8.8 HIGH | ||
| An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the removeSecondaryImage method of the Publish.php component. | |||||
| CVE-2024-31821 | 2024-07-03 | N/A | 8.0 HIGH | ||
| SQL Injection vulnerability in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the manageQuantitiesAndProcurement method of the Orders_model.php component. | |||||
| CVE-2024-31818 | 2024-07-03 | N/A | 9.8 CRITICAL | ||
| Directory Traversal vulnerability in DerbyNet v.9.0 allows a remote attacker to execute arbitrary code via the page parameter of the kiosk.php component. | |||||
| CVE-2024-31810 | 2024-07-03 | N/A | N/A | ||
| TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a hardcoded password for root at /etc/shadow.sample. | |||||
| CVE-2024-31804 | 2024-07-03 | N/A | N/A | ||
| An unquoted service path vulnerability in Terratec DMX_6Fire USB v.1.23.0.02 allows a local attacker to escalate privileges via the Program.exe component. | |||||
| CVE-2024-31801 | 2024-07-03 | N/A | 7.5 HIGH | ||
| Directory Traversal vulnerability in NEXSYS-ONE before v.Rev.15320 allows a remote attacker to obtain sensitive information via a crafted request. | |||||
| CVE-2024-31755 | 2024-07-03 | N/A | 7.6 HIGH | ||
| cJSON v1.7.17 was discovered to contain a segmentation violation, which can trigger through the second parameter of function cJSON_SetValuestring at cJSON.c. | |||||
| CVE-2024-31750 | 2024-07-03 | N/A | 9.8 CRITICAL | ||
| SQL injection vulnerability in f-logic datacube3 v.1.0 allows a remote attacker to obtain sensitive information via the req_id parameter. | |||||
| CVE-2024-31744 | 2024-07-03 | N/A | 7.5 HIGH | ||
| In Jasper 4.2.2, the jpc_streamlist_remove function in src/libjasper/jpc/jpc_dec.c:2407 has an assertion failure vulnerability, allowing attackers to cause a denial of service attack through a specific image file. | |||||
| CVE-2024-31714 | 2024-07-03 | N/A | 7.5 HIGH | ||
| Buffer Overflow vulnerability in Waxlab wax v.0.9-3 and before allows an attacker to cause a denial of service via the Lua library component. | |||||
| CVE-2024-31650 | 2024-07-03 | N/A | 9.6 CRITICAL | ||
| A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Last Name parameter. | |||||
| CVE-2024-31636 | 2024-07-03 | N/A | 3.9 LOW | ||
| An issue in LIEF v.0.14.1 allows a local attacker to obtain sensitive information via the name parameter of the machd_reader.c component. | |||||
| CVE-2024-31616 | 2024-07-03 | N/A | 8.8 HIGH | ||
| An issue discovered in RG-RSR10-01G-T(W)-S and RG-RSR10-01G-T(WA)-S routers with firmware version RSR10-01G-T-S_RSR_3.0(1)B9P2, Release(07150910) allows attackers to execute arbitrary code via the common_quick_config.lua file. | |||||
| CVE-2024-31615 | 2024-07-03 | N/A | 9.8 CRITICAL | ||
| ThinkCMF 6.0.9 is vulnerable to File upload via UeditorController.php. | |||||
| CVE-2024-31586 | 2024-07-03 | N/A | 6.1 MEDIUM | ||
| A Cross Site Scripting (XSS) vulnerability exists in Computer Laboratory Management System version 1.0. This vulnerability allows a remote attacker to execute arbitrary code via the Borrower Name, Department, and Remarks parameters. | |||||
| CVE-2024-31584 | 2024-07-03 | N/A | 5.5 MEDIUM | ||
| Pytorch before v2.2.0 has an Out-of-bounds Read vulnerability via the component torch/csrc/jit/mobile/flatbuffer_loader.cpp. | |||||
