NA - CVE-2024-48624 - In segments\edit.php of DomainMOD below...
In segments\edit.php of DomainMOD below v4.12.0, the segid parameter in the GET request can be exploited to cause a reflected Cross Site Scripting (XSS) vulnerability.
NA - CVE-2024-48913 - Hono, a web framework, prior to version 4.6.5...
Hono, a web framework, prior to version 4.6.5 is vulnerable to bypass of cross-site request forgery (CSRF) middleware by a request without Content-Type header. Although the CSRF middleware verifies...
NA - CVE-2024-48914 - Vendure is an open-source headless commerce...
Vendure is an open-source headless commerce platform. Prior to versions 3.0.5 and 2.3.3, a vulnerability in Vendure's asset server plugin allows an attacker to craft a request which is able to...
Medium - CVE-2024-9676 - A vulnerability was found in Podman, Buildah,...
A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of...
NA - CVE-2024-48915 - Agent Dart is an agent library built for...
Agent Dart is an agent library built for Internet Computer for Dart and Flutter apps. Prior to version 1.0.0-dev.29, certificate verification in `lib/agent/certificate.dart` does not occur...
NA - CVE-2024-35584 - SQL injection vulnerability in Ajax.php,...
SQL injection vulnerability in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1, 8.0, and possibly earlier versions. It is possible...
Critical - CVE-2024-21172 - Vulnerability in the Oracle Hospitality OPERA 5...
Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet). Supported versions that are affected are 5.6.19.19, 5.6.25.8 and 5.6.26.4....