In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization....
NA - CVE-2024-49379 - Umbrel is a home server OS for self-hosting....
Umbrel is a home server OS for self-hosting. The login functionality of Umbrel before version 1.2.2 contains a reflected cross-site scripting (XSS) vulnerability in use-auth.tsx. An attacker can...
NA - CVE-2023-38920 - Cross Site Scripting vulnerability in Cyber...
Cross Site Scripting vulnerability in Cyber Cafe Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted script to the adminname parameter.
NA - CVE-2024-40443 - SQL Injection vulnerability in Simple...
SQL Injection vulnerability in Simple Laboratory Management System using PHP and MySQL v.1.0 allows a remote attacker to cause a denial of service via the delete_users function in the Useres.php
NA - CVE-2024-42834 - A stored cross-site scripting (XSS)...
A stored cross-site scripting (XSS) vulnerability in the Create Customer API in Incognito Service Activation Center (SAC) UI v14.11 allows authenticated attackers to execute arbitrary web scripts...
NA - CVE-2024-11193 - An information disclosure vulnerability exists...
An information disclosure vulnerability exists in Yugabyte Anywhere, where the LDAP bind password is logged in plaintext within application logs. This flaw results in the unintentional exposure of...
NA - CVE-2024-21783 - Integer overflow for some Intel(R) VPL software...
Integer overflow for some Intel(R) VPL software before version 24.1.4 may allow an authenticated user to potentially enable escalation of privilege via local access.
NA - CVE-2024-21799 - Path traversal for some Intel(R) Extension for...
Path traversal for some Intel(R) Extension for Transformers software before version 1.5 may allow an authenticated user to potentially enable escalation of privilege via local access.
NA - CVE-2024-21808 - Improper buffer restrictions in some Intel(R)...
Improper buffer restrictions in some Intel(R) VPL software before version 24.1.4 may allow an authenticated user to potentially enable escalation of privilege via local access.
NA - CVE-2024-21820 - Incorrect default permissions in some Intel(R)...
Incorrect default permissions in some Intel(R) Xeon(R) processor memory controller configurations when using Intel(R) SGX may allow a privileged user to potentially enable escalation of privilege...