NA - CVE-2024-54450 - An issue was discovered in Kurmi Provisioning...
An issue was discovered in Kurmi Provisioning Suite 7.9.0.33. If an X-Forwarded-For header is received during authentication, the Kurmi application will record the (possibly forged) IP address...
NA - CVE-2024-54451 - A cross-site scripting (XSS) vulnerability in...
A cross-site scripting (XSS) vulnerability in the graphicCustomization.do page in Kurmi Provisioning Suite before 7.9.0.38, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15 allows remote...
NA - CVE-2024-54452 - An issue was discovered in Kurmi Provisioning...
An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35 and 7.10.x through 7.10.0.18. A Directory Traversal and Local File Inclusion vulnerability in the logsSys.do page allows remote...
NA - CVE-2024-54453 - An issue was discovered in Kurmi Provisioning...
An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15. A path traversal vulnerability in the DocServlet servlet allows remote...
NA - CVE-2024-54454 - An issue was discovered in Kurmi Provisioning...
An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15. An Observable Response Discrepancy vulnerability in the...
NA - CVE-2024-56732 - HarfBuzz is a text shaping engine. Starting...
HarfBuzz is a text shaping engine. Starting with 8.5.0 through 10.0.1, there is a heap-based buffer overflow in the hb_cairo_glyphs_from_buffer function.
NA - CVE-2024-50715 - An issue in smarts-srl.com Smart Agent v.1.1.0...
An issue in smarts-srl.com Smart Agent v.1.1.0 allows a remote attacker to obtain sensitive information via command injection through a vulnerable unsanitized parameter defined in the...
NA - CVE-2024-50716 - SQL injection vulnerability in Smart Agent...
SQL injection vulnerability in Smart Agent v.1.1.0 allows a remote attacker to execute arbitrary code via the id parameter in the /sendPushManually.php component.
NA - CVE-2024-50717 - SQL injection vulnerability in Smart Agent...
SQL injection vulnerability in Smart Agent v.1.1.0 allows a remote attacker to execute arbitrary code via the client parameter in the /recuperaLog.php component.