Medium - CVE-2024-10390 - The Elfsight Telegram Chat CC plugin for...
The Elfsight Telegram Chat CC plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the 'updatePreferences' function in all versions up...
NA - CVE-2024-43416 - GLPI is a free asset and IT management software...
GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.17, an unauthenticated user can use an application endpoint to check if an email address...
NA - CVE-2024-44757 - An arbitrary file download vulnerability in the...
An arbitrary file download vulnerability in the component /Basics/DownloadInpFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to download arbitrary files and access sensitive...
NA - CVE-2024-47533 - Cobbler, a Linux installation server that...
Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions...
NA - CVE-2024-47820 - MarkUs, a web application for the submission...
MarkUs, a web application for the submission and grading of student assignments, is vulnerable to path traversal in versions prior to 2.4.8. Authenticated instructors may download any file on the...
NA - CVE-2024-47873 - PhpSpreadsheet is a PHP library for reading and...
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. The XmlScanner class has a scan method which should prevent XXE attacks. However, prior to versions 1.9.4, 2.1.3, 2.3.2,...
NA - CVE-2024-48292 - An issue in the wssrvc.exe service of QuickHeal...
An issue in the wssrvc.exe service of QuickHeal Antivirus Pro Version v24.0 and Quick Heal Total Security v24.0 allows authenticated attackers to escalate privileges.
NA - CVE-2024-48293 - Incorrect access control in QuickHeal Antivirus...
Incorrect access control in QuickHeal Antivirus Pro 24.1.0.182 and earlier allows authenticated attackers with low-level privileges to arbitrarily modify antivirus settings.