NA - CVE-2024-38370 - GLPI is a free asset and IT management software...
GLPI is a free asset and IT management software package. Starting in 9.2.0 and prior to 11.0.0, it is possible to download a document from the API without appropriate rights. Upgrade to 10.0.16.
NA - CVE-2024-50983 - FlightPath 7.5 contains a Cross Site Scripting...
FlightPath 7.5 contains a Cross Site Scripting (XSS) vulnerability, which allows authenticated remote attackers with administrative rights to inject arbitrary JavaScript in the web browser of a...
NA - CVE-2024-51764 - A security vulnerability has been identified in...
A security vulnerability has been identified in HPE Data Management Framework (DMF) Suite (CXFS). Depending on configuration, this vulnerability may lead to local/cluster unauthorized access.
NA - CVE-2024-51765 - A security vulnerability has been identified in...
A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on configuration, this vulnerability may lead to local/cluster unauthorized access.
NA - CVE-2024-9500 - A maliciously crafted DLL file when placed in...
A maliciously crafted DLL file when placed in temporary files and folders that are leveraged by the Autodesk Installer could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to insecure...
NA - CVE-2024-11262 - A vulnerability has been found in...
A vulnerability has been found in SourceCodester Student Record Management System 1.0 and classified as critical. Affected by this vulnerability is the function main of the component View All...
NA - CVE-2024-11263 - When the Global Pointer (GP) relative...
When the Global Pointer (GP) relative addressing is enabled (CONFIG_RISCV_GP=y), the gp reg points at 0x800 bytes past the start of the .sdata section which is then used by the linker to relax...
Cisco IOS XR Software Bootloader Unauthenticated Information Disclosure Vulnerability
A vulnerability in the GRand Unified Bootloader (GRUB) for Cisco IOS XR Software could allow an unauthenticated attacker with physical access to the device to view sensitive files on the console using the GRUB bootloader command line.
NA - CVE-2024-5083 - A stored Cross-site Scripting vulnerability has...
A stored Cross-site Scripting vulnerability has been discovered in Sonatype Nexus Repository 2 This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1.