NA - CVE-2024-50376 - A CWE-79 "Improper Neutralization of Input...
A CWE-79 "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (
Medium - CVE-2024-8899 - The Jeg Elementor Kit plugin for WordPress is...
The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.9 via the render_content function in...
NA - CVE-2023-0163 - Improperly Controlled Modification of Object...
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in Mozilla Convict. This allows an attacker to inject attributes that are used in...
NA - CVE-2023-1521 - On Linux the sccache client can execute...
On Linux the sccache client can execute arbitrary code with the privileges of a local sccache server, by preloading the code in a shared library passed to LD_PRELOAD. If the server is run as root...
NA - CVE-2023-2142 - In Nunjucks versions prior to version 3.2.4, it...
In Nunjucks versions prior to version 3.2.4, it was possible to bypass the restrictions which are provided by the autoescape functionality. If there are two user-controlled parameters on the same...
NA - CVE-2024-38830 - VMware Aria Operations contains a local...
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges may trigger this vulnerability to escalate privileges to root user...
NA - CVE-2024-38831 - VMware Aria Operations contains a local...
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges can insert malicious commands into the properties file to...
NA - CVE-2024-38832 - VMware Aria Operations contains a stored...
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to views may be able to inject malicious script leading to stored cross-site...