NA - CVE-2024-9952 - A vulnerability was found in SourceCodester...
A vulnerability was found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. This issue affects some unknown processing of the file /admin/?page=system_info/contact_info of...
NA - CVE-2024-9968 - WebEIP v3.0 from
NewType does not properly...
WebEIP v3.0 from NewType does not properly validate user input, allowing remote attackers with regular privilege to inject SQL commands to read, modify, and delete data stored in database. The...
Medium - CVE-2024-9969 - NewType WebEIP v3.0 does not properly validate...
NewType WebEIP v3.0 does not properly validate user input, allowing a remote attacker with regular privileges to insert JavaScript into specific parameters, resulting in a Reflected Cross-site...
High - CVE-2024-9970 - The FlowMaster BPM Plus system from NewType has...
The FlowMaster BPM Plus system from NewType has a privilege escalation vulnerability. Remote attackers with regular privileges can elevate their privileges to administrator by tampering with a...
High - CVE-2024-9971 - The specific query functionality in the...
The specific query functionality in the FlowMaster BPM Plus from NewType does not properly restrict user input, allowing remote attackers with regular privileges to inject SQL commands to read,...
NA - CVE-2024-21535 - Versions of the package markdown-to-jsx before...
Versions of the package markdown-to-jsx before 7.4.0 are vulnerable to Cross-site Scripting (XSS) via the src property due to improper input sanitization. An attacker can execute arbitrary code by...
NA - CVE-2024-0129 - NVIDIA NeMo contains a vulnerability in...
NVIDIA NeMo contains a vulnerability in SaveRestoreConnector where a user may cause a path traversal issue via an unsafe .tar file extraction. A successful exploit of this vulnerability may lead to...
NA - CVE-2024-9944 - The WooCommerce plugin for WordPress is...
The WooCommerce plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 9.0.2. This is due to the plugin not properly neutralizing HTML elements from submitted...
NA - CVE-2024-46898 - SHIRASAGI prior to v1.19.1 processes URLs in...
SHIRASAGI prior to v1.19.1 processes URLs in HTTP requests improperly, resulting in a path traversal vulnerability. If this vulnerability is exploited, arbitrary files on the server may be...
Critical - CVE-2024-9972 - Property Management System from ChanGate has a...
Property Management System from ChanGate has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.