NA - CVE-2024-23972 - Sony XAV-AX5500 USB Configuration Descriptor...
Sony XAV-AX5500 USB Configuration Descriptor Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected...
NA - CVE-2024-34331 - A lack of code signature verification in...
A lack of code signature verification in Parallels Desktop for Mac v19.3.0 and below allows attackers to escalate privileges via a crafted macOS installer, because Parallels Service is setuid root.
NA - CVE-2024-41228 - A symlink following vulnerability in the pouch...
A symlink following vulnerability in the pouch cp function of AliyunContainerService pouch v1.3.1 allows attackers to escalate privileges and write arbitrary files.
NA - CVE-2024-46985 - DataEase is an open source data visualization...
DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, there is an XML external entity injection vulnerability in the static resource upload interface of DataEase. An...
NA - CVE-2024-46997 - DataEase is an open source data visualization...
DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, an attacker can achieve remote command execution by adding a carefully constructed h2 data source connection...
NA - CVE-2024-47066 - Lobe Chat is an open-source artificial...
Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.19.13, server-side request forgery protection implemented in `src/app/api/proxy/route.ts` does not consider...
NA - CVE-2024-47068 - Rollup is a module bundler for JavaScript....
Rollup is a module bundler for JavaScript. Versions prior to 3.29.5 and 4.22.4 are susceptible to a DOM Clobbering vulnerability when bundling scripts with properties from `import.meta` (e.g.,...
NA - CVE-2024-47069 - Oveleon Cookie Bar is a cookie bar is for the...
Oveleon Cookie Bar is a cookie bar is for the Contao Open Source CMS and allows a visitor to define cookie & privacy settings for the website. Prior to versions 1.16.3 and 2.1.3, the `block/locale`...
NA - CVE-2024-40441 - An issue in Doccano Open source annotation...
An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 allows a remote...
NA - CVE-2024-40442 - An issue in Doccano Open source annotation...
An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 allows a remote...