NA - CVE-2024-5891 - A vulnerability was found in Quay. If an...
A vulnerability was found in Quay. If an attacker can obtain the client ID for an application, they can use an OAuth token to authenticate despite not having access to the organization from which...
NA - CVE-2024-28964 - Dell Common Event Enabler, version 8.9.10.0 and...
Dell Common Event Enabler, version 8.9.10.0 and prior, contain an insecure deserialization vulnerability in CAVATools. A local unauthenticated attacker could potentially exploit this vulnerability,...
NA - CVE-2024-29181 - Strapi is an open-source content management...
Strapi is an open-source content management system. Prior to version 4.19.1, a super admin can create a collection where an item in the collection has an association to another collection. When...
NA - CVE-2024-2300 - HP Advance Mobile Applications for iOS and...
HP Advance Mobile Applications for iOS and Android are potentially vulnerable to information disclosure when using an outdated version of the application via mobile devices.
NA - CVE-2024-31217 - Strapi is an open-source content management...
Strapi is an open-source content management system. Prior to version 4.22.0, a denial-of-service vulnerability is present in the media upload process causing the server to crash without restarting,...
NA - CVE-2024-34065 - Strapi is an open-source content management...
Strapi is an open-source content management system. By combining two vulnerabilities (an `Open Redirect` and `session token sent as URL query parameter`) in @strapi/plugin-users-permissions before...
NA - CVE-2024-36265 - ** UNSUPPORTED WHEN ASSIGNED ** Incorrect...
** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Core: from 0.8.0. As this project is retired, we...
NA - CVE-2024-36691 - Insecure permissions in the...
Insecure permissions in the AdminController.AjaxSave() method of PPGo_Jobs v2.8.0 allows authenticated attackers to arbitrarily modify users' account information.
NA - CVE-2024-36840 - SQL Injection vulnerability in Boelter Blue...
SQL Injection vulnerability in Boelter Blue System Management v.1.3 allows a remote attacker to execute arbitrary code and obtain sensitive information via the id parameter to news_details.php and...