NA - CVE-2024-55885 - beego is an open-source web framework for the...
beego is an open-source web framework for the Go programming language. Versions of beego prior to 2.3.4 use MD5 as a hashing algorithm. MD5 is no longer considered secure against well-funded...
NA - CVE-2024-55886 - OpenSearch Data Prepper is a component of the...
OpenSearch Data Prepper is a component of the OpenSearch project that accepts, filters, transforms, enriches, and routes data at scale. A vulnerability exists in the OpenTelemetry Logs source in...
NA - CVE-2024-55888 - Hush Line is an open-source whistleblower...
Hush Line is an open-source whistleblower management system. Starting in version 0.1.0 and prior to version 0.3.5, the productions server appeared to have been misconfigured and missed providing...
NA - CVE-2024-21575 - ComfyUI-Impact-Pack is vulnerable to Path...
ComfyUI-Impact-Pack is vulnerable to Path Traversal. The issue stems from missing validation of the `image.filename` field in a POST request sent to the `/upload/temp` endpoint added by the...
NA - CVE-2024-55633 - Improper Authorization vulnerability in Apache...
Improper Authorization vulnerability in Apache Superset. On Postgres analytic databases an attacker with SQLLab access can craft a specially designed SQL DML statement that is Incorrectly...
NA - CVE-2024-55099 - A SQL Injection vulnerability was found in...
A SQL Injection vulnerability was found in /admin/index.php in phpgurukul Online Nurse Hiring System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized...
NA - CVE-2024-31670 - rizin before v0.6.3 is vulnerable to Buffer...
rizin before v0.6.3 is vulnerable to Buffer Overflow via create_cache_bins, read_cache_accel, and rz_dyldcache_new_buf functions in librz/bin/format/mach0/dyldcache.c.
NA - CVE-2024-47238 - Dell Client Platform BIOS contains an Improper...
Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this...