Critical - CVE-2024-1297 - Loomio version 2.22.0 allows executing...
Loomio version 2.22.0 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to OS Command Injection.
Critical - CVE-2024-1651 - Torrentpier version 2.4.1 allows executing...
Torrentpier version 2.4.1 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to insecure deserialization.
High - CVE-2024-1647 - Pyhtml2pdf version 0.0.6 allows an external...
Pyhtml2pdf version 0.0.6 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the HTML content entered by the user.
High - CVE-2024-1648 - electron-pdf version 20.0.0 allows an external...
electron-pdf version 20.0.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the HTML content entered by the user.
Medium - CVE-2023-6397 -
A null pointer dereference...
A null pointer dereference vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1 and USG FLEX series firmware versions from 4.50 through 5.37 Patch 1 could...
High - CVE-2023-6398 - A post-authentication command injection...
A post-authentication command injection vulnerability in the file upload binary in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG FLEX series firmware versions from 4.50...
Medium - CVE-2023-6399 - A format string vulnerability in Zyxel ATP...
A format string vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG FLEX series firmware versions from 4.50 through 5.37 Patch 1, USG FLEX 50(W) series firmware...