NA - CVE-2024-38288 - A command-injection issue in the Certificate...
A command-injection issue in the Certificate Signing Request (CSR) functionality in R-HUB TurboMeeting through 8.x allows authenticated attackers with administrator privileges to execute arbitrary...
NA - CVE-2024-38289 - A boolean-based SQL injection issue in the...
A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to extract hashed passwords from the...
NA - CVE-2024-40324 - A CRLF injection vulnerability in E-Staff v5.1...
A CRLF injection vulnerability in E-Staff v5.1 allows attackers to insert Carriage Return (CR) and Line Feed (LF) characters into input fields, leading to HTTP response splitting and header...
NA - CVE-2024-41808 - The OpenObserve open-source observability...
The OpenObserve open-source observability platform provides the ability to filter logs in a dashboard by the values uploaded in a given log. However, all versions of the platform through 0.9.1 do...
NA - CVE-2024-6558 - HMS Industrial Networks
Anybus-CompactCom 30...
HMS Industrial Networks Anybus-CompactCom 30 products are vulnerable to a XSS attack caused by the lack of input sanitation checks. As a consequence, it is possible to insert HTML code into input...
NA - CVE-2024-41809 - OpenObserve is an open-source observability...
OpenObserve is an open-source observability platform. Starting in version 0.4.4 and prior to version 0.10.0, OpenObserve contains a cross-site scripting vulnerability in line 32 of...
NA - CVE-2024-7105 - A vulnerability classified as critical has been...
A vulnerability classified as critical has been found in ForIP Tecnologia Administração PABX 1.x. Affected is an unknown function of the file /detalheIdUra of the component Lista Ura Page. The...
NA - CVE-2024-7106 - A vulnerability classified as problematic was...
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to...
NA - CVE-2024-36111 - KubePi is a K8s panel. Starting in version...
KubePi is a K8s panel. Starting in version 1.6.3 and prior to version 1.8.0, there is a defect in the KubePi JWT token verification. The JWT key in the default configuration file is empty. Although...
NA - CVE-2024-41806 - The Open edX Platform is a learning management...
The Open edX Platform is a learning management platform. Instructors can upload csv files containing learner information to create cohorts in the instructor dashboard. These files are uploaded...