NA - CVE-2024-24320 - Directory Traversal vulnerability in...
Directory Traversal vulnerability in Mgt-commerce CloudPanel v.2.0.0 thru v.2.4.0 allows a remote attacker to obtain sensitive information and execute arbitrary code via the service parameter of...
NA - CVE-2024-36599 - A cross-site scripting (XSS) vulnerability in...
A cross-site scripting (XSS) vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter at insertClient.php.
NA - CVE-2024-37888 - The Open Link is a CKEditor plugin, extending...
The Open Link is a CKEditor plugin, extending context menu with a possibility to open link in a new tab. The vulnerability allowed to execute JavaScript code by abusing link href attribute. It...
NA - CVE-2024-37889 - MyFinances is a web application for managing...
MyFinances is a web application for managing finances. MyFinances has a way to access other customer invoices while signed in as a user. This method allows an actor to access PII and financial...
NA - CVE-2024-21988 - StorageGRID (formerly StorageGRID Webscale)...
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.7.0.9 and 11.8.0.5 are susceptible to disclosure of sensitive information via complex MiTM attacks due to a vulnerability in the...