NA - CVE-2024-52305 - UnoPim is an open-source Product Information...
UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. A vulnerability exists in the Create User process, allowing the creation of a new admin account...
NA - CVE-2024-52306 - FileManager provides a Backpack admin interface...
FileManager provides a Backpack admin interface for files and folder. Prior to 3.0.9, deserialization of untrusted data from the mimes parameter could lead to remote code execution. This...
NA - CVE-2024-7295 - In Progress® Telerik® Report Server versions...
In Progress® Telerik® Report Server versions prior to 2024 Q4 (10.3.24.1112), the encryption of local asset data used an older algorithm which may allow a sophisticated actor to decrypt this...
NA - CVE-2024-8049 - In Progress Telerik Document Processing...
In Progress Telerik Document Processing Libraries, versions prior to 2024 Q4 (2024.4.1106), importing a document with unsupported features can lead to excessive processing, leading to excessive use...
NA - CVE-2024-45594 - Decidim is a participatory democracy framework....
Decidim is a participatory democracy framework. The meeting embeds feature used in the online or hybrid meetings is subject to potential XSS attack through a malformed URL. This vulnerability is...
NA - CVE-2024-51996 - Symphony process is a module for the Symphony...
Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. When consuming a persisted remember-me cookie, Symfony does not check if the username persisted...
NA - CVE-2024-52291 - Craft is a content management system (CMS). A...
Craft is a content management system (CMS). A vulnerability in CraftCMS allows an attacker to bypass local file system validation by utilizing a double file:// scheme (e.g., file://file:////). This...
NA - CVE-2024-52292 - Craft is a content management system (CMS). The...
Craft is a content management system (CMS). The dataUrl function can be exploited if an attacker has write permissions on system notification templates. This function accepts an absolute file path,...
NA - CVE-2024-9413 - The transport_message_handler function in...
The transport_message_handler function in SCP-Firmware release versions 2.11.0-2.15.0 does not properly handle errors, potentially allowing an Application Processor (AP) to cause a buffer overflow...
NA - CVE-2024-9476 - A vulnerability in Grafana Labs Grafana OSS and...
A vulnerability in Grafana Labs Grafana OSS and Enterprise allows Privilege Escalation allows users to gain access to resources from other organizations within the same Grafana instance via the...