NA - CVE-2024-12667 - A vulnerability was found in InvoicePlane up to...
A vulnerability was found in InvoicePlane up to 1.6.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /invoices/view. The manipulation leads to...
NA - CVE-2024-12687 - Deserialization of Untrusted Data vulnerability...
Deserialization of Untrusted Data vulnerability in PlexTrac (Runbooks modules) which allows Object Injection and arbitrary file writes. This issue affects PlexTrac: from 1.61.3 before 2.8.1.
NA - CVE-2024-55949 - MinIO is a high-performance, S3 compatible...
MinIO is a high-performance, S3 compatible object store, open sourced under GNU AGPLv3 license. Minio is subject to a privilege escalation in IAM import API, all users are impacted since MinIO...
NA - CVE-2024-55951 - Metabase is an open-source data analytics...
Metabase is an open-source data analytics platform. For new sandboxing configurations created in 1.52.0 till 1.52.2.4, sandboxed users are able to see field filter values from other sandboxed...
NA - CVE-2024-55100 - A stored cross-site scripting (XSS)...
A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Online Nurse Hiring System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a...
NA - CVE-2024-55103 - Online Nurse Hiring System v1.0 was discovered...
Online Nurse Hiring System v1.0 was discovered to contain a SQL injection vulnerability in the component /admin/profile.php via the fullname parameter.
NA - CVE-2024-55104 - Online Nurse Hiring System v1.0 was discovered...
Online Nurse Hiring System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component /admin/add-nurse.php via the gender and emailid parameters.
NA - CVE-2024-29671 - Buffer Overflow vulnerability in NEXTU FLATA...
Buffer Overflow vulnerability in NEXTU FLATA AX1500 Router v.1.0.2 allows a remote attacker to execute arbitrary code via the POST request handler component.
NA - CVE-2024-37773 - An HTML injection vulnerability in Sunbird DCIM...
An HTML injection vulnerability in Sunbird DCIM dcTrack 9.1.2 allows attackers authenticated as administrators to inject arbitrary HTML code in an admin screen.