Medium - CVE-2024-41752 - IBM Cognos Analytics 11.2.0 through 11.2.4 and...
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the...
Medium - CVE-2024-45082 - IBM Cognos Analytics 11.2.0 through 11.2.4 and...
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a...
NA - CVE-2024-55086 - In the GetSimple CMS CE 3.3.19 management page,...
In the GetSimple CMS CE 3.3.19 management page, Server-Side Request Forgery (SSRF) can be achieved in the plug-in download address in the backend management system.
NA - CVE-2024-47038 - In dhd_prot_flowrings_pool_release of...
In dhd_prot_flowrings_pool_release of dhd_msgbuf.c, there is a possible outcof bounds write due to a missing bounds check. This could lead to localcescalation of privilege with no additional...
NA - CVE-2024-47039 - In isSlotMarkedSuccessful of BootControl.cpp,...
In isSlotMarkedSuccessful of BootControl.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution...
NA - CVE-2024-47040 - There is a possible UAF due to a logic error in...
There is a possible UAF due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for...
NA - CVE-2024-49201 - Keyfactor Remote File Orchestrator (aka...
Keyfactor Remote File Orchestrator (aka remote-file-orchestrator) 2.8 before 2.8.1 allows Information Disclosure: sensitive information could be exposed at the debug logging level.