Search Results (Refine Search)
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2024-4595 |
A vulnerability has been found in SEMCMS up to 4.8 and classified as critical. Affected by this vulnerability is the function locate of the file function.php. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263317 was assigned to this vulnerability. Published: May 07, 2024; 11:15:10 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-4594 |
A vulnerability, which was classified as problematic, was found in DedeCMS 5.7. Affected is an unknown function of the file /src/dede/sys_safe.php. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263316. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Published: May 07, 2024; 11:15:10 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-34523 |
AChecker 1.5 allows remote attackers to read the contents of arbitrary files via the download.php path parameter by using Unauthenticated Path Traversal. This occurs through readfile in PHP. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. Published: May 07, 2024; 11:15:09 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-34342 |
react-pdf displays PDFs in React apps. If PDF.js is used to load a malicious PDF, and PDF.js is configured with `isEvalSupported` set to `true` (which is the default value), unrestricted attacker-controlled JavaScript will be executed in the context of the hosting domain. This vulnerability is fixed in 7.7.3 and 8.0.2. Published: May 07, 2024; 11:15:09 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-34084 |
Minder's `HandleGithubWebhook` is susceptible to a denial of service attack from an untrusted HTTP request. The vulnerability exists before the request has been validated, and as such the request is still untrusted at the point of failure. This allows an attacker with the ability to send requests to `HandleGithubWebhook` to crash the Minder controlplane and deny other users from using it. This vulnerability is fixed in 0.0.48. Published: May 07, 2024; 11:15:09 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-33124 |
Roothub v2.6 was discovered to contain a SQL injection vulnerability via the nodeTitle parameter in the parentNode() function.. Published: May 07, 2024; 11:15:09 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-33122 |
Roothub v2.6 was discovered to contain a SQL injection vulnerability via the topic parameter in the list() function. Published: May 07, 2024; 11:15:09 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-33120 |
Roothub v2.5 was discovered to contain an arbitrary file upload vulnerability via the customPath parameter in the upload() function. This vulnerability allows attackers to execute arbitrary code via a crafted JSP file. Published: May 07, 2024; 11:15:09 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-32867 |
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.5 and 6.0.19, various problems in handling of fragmentation anomalies can lead to mis-detection of rules and policy. This vulnerability is fixed in 7.0.5 or 6.0.19. Published: May 07, 2024; 11:15:09 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-32664 |
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.5 and 6.0.19, specially crafted traffic or datasets can cause a limited buffer overflow. This vulnerability is fixed in 7.0.5 and 6.0.19. Workarounds include not use rules with `base64_decode` keyword with `bytes` option with value 1, 2 or 5 and for 7.0.x, setting `app-layer.protocols.smtp.mime.body-md5` to false. Published: May 07, 2024; 11:15:08 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-32663 |
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.5 and 6.0.19, a small amount of HTTP/2 traffic can lead to Suricata using a large amount of memory. The issue has been addressed in Suricata 7.0.5 and 6.0.19. Workarounds include disabling the HTTP/2 parser and reducing `app-layer.protocols.http2.max-table-size` value (default is 65536). Published: May 07, 2024; 11:15:08 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-32371 |
An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a regular user account to escalate their privileges and gain administrative access by changing the type parameter from 1 to 0. Published: May 07, 2024; 11:15:08 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-32370 |
An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive information via a crafted payload to the id parameter in the mliSystemUsers.php component. Published: May 07, 2024; 11:15:08 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-32369 |
SQL Injection vulnerability in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive information via a crafted payload to the start and limit parameter in the mliWhiteList.php component. Published: May 07, 2024; 11:15:08 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-4593 |
A vulnerability, which was classified as problematic, has been found in DedeCMS 5.7. This issue affects some unknown processing of the file /src/dede/sys_multiserv.php. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263315. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Published: May 07, 2024; 10:15:11 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-4592 |
A vulnerability classified as problematic was found in DedeCMS 5.7. This vulnerability affects unknown code of the file /src/dede/sys_group_edit.php. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-263314 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Published: May 07, 2024; 10:15:11 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-4591 |
A vulnerability classified as problematic has been found in DedeCMS 5.7. This affects an unknown part of the file /src/dede/sys_group_add.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263313 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Published: May 07, 2024; 10:15:11 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-4590 |
A vulnerability was found in DedeCMS 5.7. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /src/dede/sys_info.php. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263312. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Published: May 07, 2024; 10:15:11 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-33783 |
MP-SPDZ v0.3.8 was discovered to contain a segmentation violation via the function osuCrypto::SilentMultiPprfReceiver::expand in /Tools/SilentPprf.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted message. Published: May 07, 2024; 10:15:10 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-33782 |
MP-SPDZ v0.3.8 was discovered to contain a stack overflow via the function OTExtensionWithMatrix::extend in /OT/OTExtensionWithMatrix.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted message. Published: May 07, 2024; 10:15:10 AM -0400 |
V3.x:(not available) V2.0:(not available) |