NA - CVE-2024-43090 - In multiple locations, there is a possible...
In multiple locations, there is a possible cross-user image read due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User...
NA - CVE-2024-43091 - In filterMask of SkEmbossMaskFilter.cpp, there...
In filterMask of SkEmbossMaskFilter.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed....
In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization....
NA - CVE-2024-49379 - Umbrel is a home server OS for self-hosting....
Umbrel is a home server OS for self-hosting. The login functionality of Umbrel before version 1.2.2 contains a reflected cross-site scripting (XSS) vulnerability in use-auth.tsx. An attacker can...
NA - CVE-2023-38920 - Cross Site Scripting vulnerability in Cyber...
Cross Site Scripting vulnerability in Cyber Cafe Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted script to the adminname parameter.
NA - CVE-2024-40443 - SQL Injection vulnerability in Simple...
SQL Injection vulnerability in Simple Laboratory Management System using PHP and MySQL v.1.0 allows a remote attacker to cause a denial of service via the delete_users function in the Useres.php
NA - CVE-2024-42834 - A stored cross-site scripting (XSS)...
A stored cross-site scripting (XSS) vulnerability in the Create Customer API in Incognito Service Activation Center (SAC) UI v14.11 allows authenticated attackers to execute arbitrary web scripts...
NA - CVE-2024-11193 - An information disclosure vulnerability exists...
An information disclosure vulnerability exists in Yugabyte Anywhere, where the LDAP bind password is logged in plaintext within application logs. This flaw results in the unintentional exposure of...
NA - CVE-2024-21783 - Integer overflow for some Intel(R) VPL software...
Integer overflow for some Intel(R) VPL software before version 24.1.4 may allow an authenticated user to potentially enable escalation of privilege via local access.
NA - CVE-2024-21799 - Path traversal for some Intel(R) Extension for...
Path traversal for some Intel(R) Extension for Transformers software before version 1.5 may allow an authenticated user to potentially enable escalation of privilege via local access.