NA - CVE-2024-44943 - In the Linux kernel, the following...
In the Linux kernel, the following vulnerability has been resolved: mm: gup: stop abusing try_grab_folio A kernel warning was reported when pinning folio in CMA memory when launching SEV virtual...
NA - CVE-2024-5546 - Zohocorp ManageEngine Password Manager Pro...
Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Injection vulnerability via a global search option.
NA - CVE-2024-7269 - Improper Neutralization of Input During Web...
Improper Neutralization of Input During Web Page Generation vulnerability in "Update of Personal Details" form in ConnX ESP HR Management allows Stored XSS attack. An attacker might inject a script...
NA - CVE-2024-6449 - HyperView Geoportal Toolkit in versions though...
HyperView Geoportal Toolkit in versions though 8.2.4 does not restrict cross-domain requests when fetching remote content pointed by one of GET request parameters. An unauthenticated remote...
NA - CVE-2024-6450 - HyperView Geoportal Toolkit in versions though...
HyperView Geoportal Toolkit in versions though 8.2.4 is vulnerable to Reflected Cross-Site Scripting (XSS). An unauthenticated attacker might trick somebody into using a crafted URL, which will...
Medium - CVE-2024-7447 - The Interactive Contact Form and Multi Step...
The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing...
NA - CVE-2024-8195 - The Permalink Manager Lite plugin for WordPress...
The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'debug_data', 'debug_query', and...
NA - CVE-2024-34198 - TOTOLINK AC1200 Wireless Router A3002RU...
TOTOLINK AC1200 Wireless Router A3002RU V2.1.1-B20230720.1011 is vulnerable to Buffer Overflow. The formWlEncrypt CGI handler in the boa program fails to limit the length of the wlan_ssid field...
NA - CVE-2024-42698 - Roughly Enough Items (REI) v.16.0.729 and...
Roughly Enough Items (REI) v.16.0.729 and before contains an Improper Validation of Specified Index, Position, or Offset in Input vulnerability. The specific issue is a failure to validate slot...
NA - CVE-2024-42900 - Ruoyi v4.7.9 and before was discovered to...
Ruoyi v4.7.9 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the sql parameter of the createTable() function at /tool/gen/create.