NA - CVE-2024-41119 - streamlit-geospatial is a streamlit multipage...
streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `vis_params` variable on line 80 in...
NA - CVE-2024-41120 - streamlit-geospatial is a streamlit multipage...
streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `url` variable on line 63 of...
NA - CVE-2024-41628 - Directory Traversal vulnerability in...
Directory Traversal vulnerability in Severalnines Cluster Control 1.9.8 before 1.9.8-9778, 2.0.0 before 2.0.0-9779, and 2.1.0 before 2.1.0-9780 allows a remote attacker to include and display file...
NA - CVE-2024-41815 - Starship is a cross-shell prompt. Starting in...
Starship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause...
NA - CVE-2024-40689 - IBM InfoSphere Information Server 11.7 is...
IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete...
NA - CVE-2024-6922 - Automation Anywhere Automation 360 v21-v32 is...
Automation Anywhere Automation 360 v21-v32 is vulnerable to Server-Side Request Forgery in a web API component. An attacker with unauthenticated access to the Automation 360 Control Room HTTPS...
NA - CVE-2024-7128 - A flaw was found in the Openshift console....
A flaw was found in the Openshift console. Several endpoints in the application use the authHandler() and authHandlerWithUser() middleware functions. When the default authentication provider...
NA - CVE-2024-41670 - In the module "PayPal Official" for PrestaShop...
In the module "PayPal Official" for PrestaShop 7+ releases prior to version 6.4.2 and for PrestaShop 1.6 releases prior to version 3.18.1, a malicious customer can confirm an order even if payment...
NA - CVE-2024-41805 - Tracks, a Getting Things Done (GTD) web...
Tracks, a Getting Things Done (GTD) web application, is vulnerable to reflected cross-site scripting in versions prior to 2.7.1. Reflected cross-site scripting enables execution of malicious...