NA - CVE-2024-47136 - Out-of-bounds read vulnerability exists in...
Out-of-bounds read vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.14.0 and earlier. Having a user open a specially crafted project...
High - CVE-2024-8352 - The Social Web Suite – Social Media Auto Post,...
The Social Web Suite – Social Media Auto Post, Social Media Auto Publish plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.1.11 via the download_log...
NA - CVE-2024-47561 - Schema parsing in the Java SDK of Apache Avro...
Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code. Users are recommended to upgrade to version 1.11.4 or 1.12.0, which fix this...
NA - CVE-2024-9313 - Authd PAM module before version 0.3.5 can allow...
Authd PAM module before version 0.3.5 can allow broker-managed users to impersonate any other user managed by the same broker and perform any PAM operation with it, including authenticating as them.
NA - CVE-2024-47554 - Uncontrolled Resource Consumption vulnerability...
Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously...
NA - CVE-2024-47614 - async-graphql is a GraphQL server library...
async-graphql is a GraphQL server library implemented in Rust. async-graphql before 7.0.10 does not limit the number of directives for a field. This can lead to Service Disruption, Resource...
NA - CVE-2024-47617 - Sulu is a PHP content management system. This...
Sulu is a PHP content management system. This vulnerability allows an attacker to inject arbitrary HTML/JavaScript code through the media download URL in Sulu CMS. It affects the SuluMediaBundle...
NA - CVE-2024-47618 - Sulu is a PHP content management system. Sulu...
Sulu is a PHP content management system. Sulu is vulnerable against XSS whereas a low privileged user with access to the “Media” section can upload an SVG file with a malicious payload. Once...