Medium - CVE-2024-9979 - A flaw was found in PyO3. This vulnerability...
A flaw was found in PyO3. This vulnerability causes a use-after-free issue, potentially leading to memory corruption or crashes via unsound borrowing from weak Python references.
NA - CVE-2023-31493 - RCE (Remote Code Execution) exists in...
RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language folder, while executing a crafted payload and escalate privileges allowing...
NA - CVE-2024-47080 - matrix-js-sdk is the Matrix Client-Server SDK...
matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript. In matrix-js-sdk versions versions 9.11.0 through 34.7.0, the method `MatrixClient.sendSharedHistoryKeys` is vulnerable...
NA - CVE-2024-47771 - Element Desktop is a Matrix client for desktop...
Element Desktop is a Matrix client for desktop platforms. Element Desktop versions 1.11.70 through 1.11.80 contain a vulnerability which can, under specially crafted conditions, lead to the access...
NA - CVE-2024-47779 - Element is a Matrix web client built using the...
Element is a Matrix web client built using the Matrix React SDK .Element Web versions 1.11.70 through 1.11.80 contain a vulnerability which can, under specially crafted conditions, lead to the...
NA - CVE-2024-47824 - matrix-react-sdk is react-based software...
matrix-react-sdk is react-based software development kit for inserting a Matrix chat/VOIP client into a web page. Starting in version 3.18.0 and before 3.102.0, matrix-react-sdk allows a malicious...
NA - CVE-2024-47874 - Starlette is an Asynchronous Server Gateway...
Starlette is an Asynchronous Server Gateway Interface (ASGI) framework/toolkit. Prior to version 0.40.0, Starlette treats `multipart/form-data` parts without a `filename` as text form fields and...
NA - CVE-2024-47876 - Sakai is a Collaboration and Learning...
Sakai is a Collaboration and Learning Environment. Starting in version 23.0 and prior to version 23.2, kernel users created with type roleview can log in as a normal user. This can result in...
NA - CVE-2024-48622 - A cross-site scripting (XSS) issue in DomainMOD...
A cross-site scripting (XSS) issue in DomainMOD below v4.12.0 allows remote attackers to inject JavaScript code via admin/domain-fields/edit.php and the cdfid parameter.
NA - CVE-2024-48623 - In queue\index.php of DomainMOD below v4.12.0,...
In queue\index.php of DomainMOD below v4.12.0, the list_id and domain_id parameters in the GET request can be exploited to cause a reflected Cross Site Scripting (XSS).