NA - CVE-2024-38652 - Path traversal in the skin management component...
Path traversal in the skin management component of Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to achieve denial of service via arbitrary file deletion.
NA - CVE-2024-7728 - The specific CGI of the CAYIN Technology CMS...
The specific CGI of the CAYIN Technology CMS does not properly validate user input, allowing a remote attacker with administrator privileges to inject OS commands into the specific parameter and...
NA - CVE-2024-7588 - The Gutenberg Blocks, Page Builder –...
The Gutenberg Blocks, Page Builder – ComboBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Accordion block in all versions up to, and including, 2.2.87...
Critical - CVE-2024-7731 - Dr.ID Access Control System from SECOM does not...
Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database...
Critical - CVE-2024-7732 - Dr.ID Access Control System from SECOM does not...
Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database...
High - CVE-2024-41858 - InCopy versions 18.5.2, 19.4 and earlier are...
InCopy versions 18.5.2, 19.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user....
Medium - CVE-2024-41860 - Substance3D - Sampler versions 4.5 and earlier...
Substance3D - Sampler versions 4.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability...
Medium - CVE-2024-41861 - Substance3D - Sampler versions 4.5 and earlier...
Substance3D - Sampler versions 4.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability...