NA - CVE-2024-22117 - When a URL is added to the map element, it is...
When a URL is added to the map element, it is recorded in the database with sequential IDs. Upon adding a new URL, the system retrieves the last sysmapelementurlid value and increments it by one....
NA - CVE-2024-52336 - A script injection vulnerability was identified...
A script injection vulnerability was identified in the Tuned package. The `instance_create()` D-Bus function can be called by locally logged-in users without authentication. This flaw allows a...
NA - CVE-2024-52337 - A log spoofing flaw was found in the Tuned...
A log spoofing flaw was found in the Tuned package due to improper sanitization of some API arguments. This flaw allows an attacker to pass a controlled sequence of characters; newlines can be...
NA - CVE-2024-11407 - There exists a denial of service through Data...
There exists a denial of service through Data corruption in gRPC-C++ - gRPC-C++ servers with transmit zero copy enabled through the channel arg GRPC_ARG_TCP_TX_ZEROCOPY_ENABLED can experience data...
NA - CVE-2024-53365 - A stored cross-site scripting (XSS)...
A stored cross-site scripting (XSS) vulnerability was identified in PHPGURUKUL Vehicle Parking Management System v1.13 in /users/profile.php. This vulnerability allows authenticated users to inject...
Medium - CVE-2024-10878 - The Sugar Calendar – Simple Event Management...
The Sugar Calendar – Simple Event Management plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on...
NA - CVE-2024-51058 - Local File Inclusion (LFI) vulnerability has...
Local File Inclusion (LFI) vulnerability has been discovered in TCPDF 6.7.5. This vulnerability enables a user to read arbitrary files from the server's file system through src tag,...