NA - CVE-2024-34195 - TOTOLINK AC1200 Wireless Router A3002R Firmware...
TOTOLINK AC1200 Wireless Router A3002R Firmware V1.1.1-B20200824 is vulnerable to Buffer Overflow. In the boa server program's CGI handling function formWlEncrypt, there is a lack of length...
NA - CVE-2024-42793 - A Cross-Site Request Forgery (CSRF)...
A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via a crafted request to the /music/ajax.php?action=save_user page.
NA - CVE-2024-43805 - jupyterlab is an extensible environment for...
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. This vulnerability depends on user interaction by opening a malicious...
NA - CVE-2024-44760 - Incorrect access control in the component...
Incorrect access control in the component /servlet/SnoopServlet of Shenzhou News Union Enterprise Management System v5.0 through v18.8 allows attackers to access sensitive information regarding the...
NA - CVE-2024-45043 - The OpenTelemetry Collector module AWS firehose...
The OpenTelemetry Collector module AWS firehose receiver is for ingesting AWS Kinesis Data Firehose delivery stream messages and parsing the records received based on the configured record type....
NA - CVE-2024-45054 - Hwameistor is an HA local storage system for...
Hwameistor is an HA local storage system for cloud-native stateful workloads. This ClusterRole has * verbs of * resources. If a malicious user can access the worker node which has hwameistor's...
NA - CVE-2024-45046 - PHPSpreadsheet is a pure PHP library for...
PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In affected versions `\PhpOffice\PhpSpreadsheet\Writer\Html` doesn't sanitize spreadsheet styling information...
NA - CVE-2024-45048 - PHPSpreadsheet is a pure PHP library for...
PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Affected versions are subject to a bypassing of a filter which allows for an XXE-attack. This in turn allows attacker...
NA - CVE-2024-45057 - i-Educar is free, completely online school...
i-Educar is free, completely online school management software that allows school secretaries, teachers, coordinators and area managers. The lack of sanitization of user-controlled parameters for...
NA - CVE-2024-45058 - i-Educar is free, completely online school...
i-Educar is free, completely online school management software that allows school secretaries, teachers, coordinators and area managers. An attacker with only minimal viewing privileges in the...