NA - CVE-2024-48294 - A NULL pointer dereference in the component...
A NULL pointer dereference in the component libPdfCore.dll of Wondershare PDF Reader v1.0.9.2544 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
NA - CVE-2024-48917 - PhpSpreadsheet is a PHP library for reading and...
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. The `XmlScanner` class has a scan method which should prevent XXE attacks. However, in a bypass of the previously reported...
NA - CVE-2024-50919 - Jpress until v5.1.1 has arbitrary file uploads...
Jpress until v5.1.1 has arbitrary file uploads on the windows platform, and the construction of non-standard file formats such as .jsp. can lead to arbitrary command execution
NA - CVE-2024-51499 - MarkUs is a web application for the submission...
MarkUs is a web application for the submission and grading of student assignments. In versions prior to 2.4.8, an arbitrary file write vulnerability accessible via the update_files method of the...
NA - CVE-2024-51743 - MarkUs is a web application for the submission...
MarkUs is a web application for the submission and grading of student assignments. In versions prior to 2.4.8, an arbitrary file write vulnerability in the update/upload/create file methods in...
NA - CVE-2024-52303 - aiohttp is an asynchronous HTTP client/server...
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In versions starting with 3.10.6 and prior to 3.10.11, a memory leak can occur when a request produces a...
NA - CVE-2024-50804 - Insecure Permissions vulnerability in...
Insecure Permissions vulnerability in Micro-star International MSI Center Pro 2.1.37.0 allows a local attacker to execute arbitrary code via the Device_DeviceID.dat.bak file within the...
NA - CVE-2024-50848 - An XML External Entity (XXE) vulnerability in...
An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to access sensitive information and execute arbitrary commands...
NA - CVE-2024-51053 - An arbitrary file upload vulnerability in the...
An arbitrary file upload vulnerability in the component /main/fileupload.php of AVSCMS v8.2.0 allows attackers to execute arbitrary code via uploading a crafted file.