NA - CVE-2024-39843 - A SQL injection vulnerability in Centreon...
A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL command via create user form inputs.
NA - CVE-2024-37779 - WoodWing Elvis DAM v6.98.1 was discovered to...
WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the Apache Ant script functionality.
NA - CVE-2024-43201 - The Planet Fitness Workouts iOS and Android...
The Planet Fitness Workouts iOS and Android mobile apps prior to version 9.8.12 (released on 2024-07-25) fail to properly validate TLS certificates, allowing an attacker with appropriate network...
NA - CVE-2024-44540 - Ubiquiti AirMax firmware version firmware...
Ubiquiti AirMax firmware version firmware version 8 allows attackers with physical access to gain a privileged command shell via the UART Debugging Port.
NA - CVE-2024-46639 - A cross-site scripting (XSS) vulnerability in...
A cross-site scripting (XSS) vulnerability in HelpDeskZ v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name text field of Custom Fields...
NA - CVE-2024-47222 - New Cloud MyOffice SDK Collaborative Editing...
New Cloud MyOffice SDK Collaborative Editing Server 2.2.2 through 2.8 allows SSRF via manipulation of requests from external document storage via the MS-WOPI protocol.
NA - CVE-2024-42861 - An issue in IEEE 802.1AS linuxptp v.4.2 and...
An issue in IEEE 802.1AS linuxptp v.4.2 and before allowing a remote attacker to cause a denial of service via a crafted Pdelay_Req message to the time synchronization function
NA - CVE-2024-8263 - An improper privilege management vulnerability...
An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use of nested tags. This vulnerability affected all versions of...
NA - CVE-2024-8770 - A Cross-Site Scripting (XSS) vulnerability was...
A Cross-Site Scripting (XSS) vulnerability was identified in the repository transfer feature of GitHub Enterprise Server, which allows attackers to steal sensitive user information via social...
NA - CVE-2018-20072 - Insufficient data validation in PDF in Google...
Insufficient data validation in PDF in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform out of bounds memory access via a crafted PDF file. (Chromium security severity: Low)