NA - CVE-2024-7071 - Improper Neutralization of Special Elements...
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 564 - SQL Injection: Hibernate vulnerability in Brain Information Technologies Inc. Brain...
NA - CVE-2024-6632 - A vulnerability exists in FileCatalyst Workflow...
A vulnerability exists in FileCatalyst Workflow whereby a field accessible to the super admin can be used to perform an SQL injection attack which can lead to a loss of confidentiality, integrity,...
NA - CVE-2024-6633 - The default credentials for the setup HSQL...
The default credentials for the setup HSQL database (HSQLDB) for FileCatalyst Workflow are published in a vendor knowledgebase article. Misuse of these credentials could lead to a compromise of...
NA - CVE-2024-40395 - An Insecure Direct Object Reference (IDOR) in...
An Insecure Direct Object Reference (IDOR) in PTC ThingWorx v9.5.0 allows attackers to view sensitive information, including PII, regardless of access level.
NA - CVE-2024-41622 - D-Link DIR-846W A1 FW100A43 was discovered to...
D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address parameter in /HNAP1/ interface.
NA - CVE-2024-44340 - D-Link DIR-846W A1 FW100A43 was discovered to...
D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via keys smartqos_express_devices and smartqos_normal_devices in SetSmartQoSSettings.
NA - CVE-2024-44341 - D-Link DIR-846W A1 FW100A43 was discovered to...
D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter. This vulnerability is exploited via a crafted POST...
NA - CVE-2024-44342 - D-Link DIR-846W A1 FW100A43 was discovered to...
D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the wl(0).(0)_ssid parameter. This vulnerability is exploited via a crafted POST request.
NA - CVE-2024-45264 - A cross-site request forgery (CSRF)...
A cross-site request forgery (CSRF) vulnerability in the admin panel in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to add a new administrator, leading to escalation of privileges.
Medium - CVE-2024-8199 - The Reviews Feed – Add Testimonials and...
The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for WordPress is vulnerable to unauthorized modification of data due to a missing...