NA - CVE-2024-7578 - A vulnerability was found in Alien Technology...
A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been classified as critical. Affected is an unknown function of the file /var/www/cmd.php. The manipulation of the...
NA - CVE-2024-3973 - The House Manager WordPress plugin through...
The House Manager WordPress plugin through 1.0.8.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used...
NA - CVE-2024-6494 - The WordPress File Upload WordPress plugin...
The WordPress File Upload WordPress plugin before 4.24.8 does not properly sanitize and escape certain parameters, which could allow unauthenticated users to execute stored cross-site scripting...
NA - CVE-2024-42062 - CloudStack account-users by default use...
CloudStack account-users by default use username and password based authentication for API and UI access. Account-users can generate and register randomised API and secret keys and use them for the...
NA - CVE-2024-42222 - In Apache CloudStack 4.19.1.0, a regression in...
In Apache CloudStack 4.19.1.0, a regression in the network listing API allows unauthorised list access of network details for domain admin and normal user accounts. This vulnerability compromises...
NA - CVE-2024-5290 - An issue was discovered in Ubuntu...
An issue was discovered in Ubuntu wpa_supplicant that resulted in loading of arbitrary shared objects, which allows a local unprivileged attacker to escalate privileges to the user that...
NA - CVE-2024-34604 - Improper access control in LedCoverService...
Improper access control in LedCoverService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
NA - CVE-2024-34605 - Improper access control in SamsungHealthService...
Improper access control in SamsungHealthService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
NA - CVE-2024-34606 - Improper access control in SmartThingsService...
Improper access control in SmartThingsService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
NA - CVE-2024-34607 - Improper access control in SamsungNotesService...
Improper access control in SamsungNotesService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.