High - CVE-2024-38183 - An improper access control vulnerability in...
An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network by convincing a user to click on a malicious link.
High - CVE-2024-43460 - Improper authorization in Dynamics 365 Business...
Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacker to elevate privileges over a network.
NA - CVE-2024-45384 - Padding Oracle vulnerability in Apache Druid...
Padding Oracle vulnerability in Apache Druid extension, druid-pac4j. This could allow an attacker to manipulate a pac4j session cookie. This issue affects Apache Druid versions 0.18.0 through...
NA - CVE-2024-45537 - Apache Druid allows users with certain...
Apache Druid allows users with certain permissions to read data from other database systems using JDBC. This functionality allows trusted users to set up Druid lookups or run ingestion tasks. Druid...
NA - CVE-2024-45612 - Contao is an Open Source CMS. In affected...
Contao is an Open Source CMS. In affected versions an untrusted user can inject insert tags into the canonical tag, which are then replaced on the web page (front end). Users are advised to update...
NA - CVE-2024-45798 - arduino-esp32 is an Arduino core for the ESP32,...
arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. The `arduino-esp32` CI is vulnerable to multiple Poisoned Pipeline Execution...
NA - CVE-2024-45803 - Wire UI is a library of components and...
Wire UI is a library of components and resources to empower Laravel and Livewire application development. A potential Cross-Site Scripting (XSS) vulnerability has been identified in the...
NA - CVE-2024-8660 - Concrete CMS versions 9.0.0 through 9.3.3 are...
Concrete CMS versions 9.0.0 through 9.3.3 are affected by a stored XSS vulnerability in the "Top Navigator Bar" block. Since the "Top Navigator Bar" output was not sufficiently sanitized, a rogue...
NA - CVE-2024-8900 - An attacker could write data to the user's...
An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events. This vulnerability affects Firefox < 129.
NA - CVE-2024-8946 - A vulnerability was found in MicroPython...
A vulnerability was found in MicroPython 1.23.0. It has been classified as critical. Affected is the function mp_vfs_umount of the file extmod/vfs.c of the component VFS Unmount Handler. The...