NA - CVE-2024-23454 - Apache Hadoop’s RunJar.run() does not set...
Apache Hadoop’s RunJar.run() does not set permissions for temporary directory by default. If sensitive data will be present in this file, all the other local users may be able to view the content....
NA - CVE-2024-40761 - Inadequate Encryption Strength vulnerability in...
Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. Using the MD5 value of a user's email to access Gravatar is insecure and can...
NA - CVE-2024-47303 - Improper Neutralization of Input During Web...
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Livemesh Livemesh Addons for Elementor allows Stored XSS.This issue affects...
Medium - CVE-2024-9169 - The LiteSpeed Cache plugin for WordPress is...
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin debug settings in all versions up to, and including, 6.4.1 due to insufficient input sanitization...
High - CVE-2021-38963 - IBM Aspera Console 3.4.0 through 3.4.4 could...
IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a CSV injection vulnerability. By persuading a victim to open a...
Low - CVE-2022-43845 - IBM Aspera Console 3.4.0 through 3.4.4 could...
IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this...
NA - CVE-2023-26686 - File Upload vulnerability in CS-Cart...
File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the image upload feature when customizing a shop.
NA - CVE-2023-26687 - Directory Traversal vulnerability in CS-Cart...
Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to obtain sensitive information via the product_data parameter in the PDF Add-on.
NA - CVE-2023-26688 - Cross Site Scripting (XSS) vulnerability in...
Cross Site Scripting (XSS) vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the product_data parameter of add/edit product in the administration interface.