Low - CVE-2024-12970 - Improper Neutralization of Special Elements...
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TUBITAK BILGEM Pardus OS My Computer allows OS Command Injection.This issue...
NA - CVE-2024-5594 - OpenVPN before 2.6.11 does not santize...
OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which attackers can use to inject unexpected arbitrary data into third-party executables or plug-ins.
NA - CVE-2024-46209 - A stored cross-site scripting (XSS)...
A stored cross-site scripting (XSS) vulnerability in the component /media/test.html of REDAXO CMS v5.17.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload...
NA - CVE-2024-55407 - An issue in the DeviceloControl function of ITE...
An issue in the DeviceloControl function of ITE Tech. Inc ITE IO Access v1.0.0.0 allows attackers to perform arbitrary port read and write actions via supplying crafted IOCTL requests.
NA - CVE-2024-55408 - An issue in the AsusSAIO.sys component of ASUS...
An issue in the AsusSAIO.sys component of ASUS System Analysis IO v1.0.0 allows attackers to perform arbitrary read and write actions via supplying crafted IOCTL requests.
NA - CVE-2024-55074 - The edit profile function of Grocy through...
The edit profile function of Grocy through 4.3.0 allows stored XSS and resultant privilege escalation by uploading a crafted HTML or SVG file, a different issue than CVE-2024-8370.
NA - CVE-2025-21617 - Guzzle OAuth Subscriber signs Guzzle requests...
Guzzle OAuth Subscriber signs Guzzle requests using OAuth 1.0. Prior to 0.8.1, Nonce generation does not use sufficient entropy nor a cryptographically secure pseudorandom source. This can leave...