NA - CVE-2024-45346 - The Xiaomi Security Center expresses heartfelt...
The Xiaomi Security Center expresses heartfelt thanks to Ken Gannon and Ilyes Beghdadi of NCC Group working with Trend Micro Zero Day Initiative! At the same time, we also welcome more outstanding...
NA - CVE-2024-4554 - Improper Input Validation vulnerability in...
Improper Input Validation vulnerability in OpenText NetIQ Access Manager leads to Cross-Site Scripting (XSS) attack. This issue affects NetIQ Access Manager before 5.0.4.1 and 5.1.
NA - CVE-2024-4555 - Improper Privilege Management vulnerability in...
Improper Privilege Management vulnerability in OpenText NetIQ Access Manager allows user account impersonation in specific scenario. This issue affects NetIQ Access Manager before 5.0.4.1 and...
NA - CVE-2024-4556 - Improper Limitation of a Pathname to a...
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText NetIQ Access Manager allows access the sensitive information. This issue affects...
High - CVE-2024-6311 - The Funnelforms Free plugin for WordPress is...
The Funnelforms Free plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'af2_add_font' function in all versions up to, and including,...
Medium - CVE-2024-6312 - The Funnelforms Free plugin for WordPress is...
The Funnelforms Free plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 3.7.3.2 via the 'af2DeleteFontFile' function. This is due to the...
NA - CVE-2023-26321 - A path traversal vulnerability exists in the...
A path traversal vulnerability exists in the Xiaomi File Manager application product(international version). The vulnerability is caused by unfiltered special characters and can be exploited by...
NA - CVE-2023-26322 - A code execution vulnerability exists in the...
A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability...
NA - CVE-2023-26323 - A code execution vulnerability exists in the...
A code execution vulnerability exists in the Xiaomi App market product. The vulnerability is caused by unsafe configuration and can be exploited by attackers to execute arbitrary code.
NA - CVE-2023-26324 - A code execution vulnerability exists in the...
A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability...