Category: CVE

CVE-2024-47873 | PHPOffice PhpSpreadsheet up to 1.29.3/2.1.2/2.3.1/3.3.x scan/findCharSet xml external entity reference (GHSA-jw4x-v69f-hh5w)

A vulnerability was found in PHPOffice PhpSpreadsheet up to 1.29.3/2.1.2/2.3.1/3.3.x and classified as critical. Affected by this issue is the function scan/findCharSet. The manipulation leads to xml external entity reference. This vulnerability is handled as CVE-2024-47873. The attack may be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-52424 | Suresh Kumar wp-login customizer Plugin up to 1.0 on WordPress cross-site request forgery

A vulnerability has been found in Suresh Kumar wp-login customizer Plugin up to 1.0 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. This vulnerability is known as CVE-2024-52424. The attack can be launched remotely. There is no exploit...

Read More

CVE-2024-47820 | MarkUsProject Markus up to 2.4.7 path traversal (GHSA-wq6v-vx8c-8fj8)

A vulnerability classified as critical has been found in MarkUsProject Markus up to 2.4.7. This affects an unknown part. The manipulation leads to path traversal. This vulnerability is uniquely identified as CVE-2024-47820. Access to the local network is required for this attack to succeed. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-44756 | NUS-M9 ERP Management Software 3.0.0 /UserWH/checkLogin usercode sql injection

A vulnerability was found in NUS-M9 ERP Management Software 3.0.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /UserWH/checkLogin. The manipulation of the argument usercode leads to sql injection. This vulnerability is handled as CVE-2024-44756. The attack may be launched remotely. There is no exploit...

Read More

CVE-2024-43416 | GLPI up to 10.0.16 information disclosure

A vulnerability was found in GLPI up to 10.0.16. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to information disclosure. This vulnerability is known as CVE-2024-43416. The attack can be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-44757 | NUS-M9 ERP Management Software 3.0.0 /Basics/DownloadInpFile information disclosure

A vulnerability was found in NUS-M9 ERP Management Software 3.0.0. It has been classified as problematic. Affected is an unknown function of the file /Basics/DownloadInpFile. The manipulation leads to information disclosure. This vulnerability is traded as CVE-2024-44757. The attack needs to be done within the local network. There is no exploit...

Read More

CVE-2024-52574 | Siemens Tecnomatix Plant Simulation prior 2302.0018/2404.0007 WRL File out-of-bounds (ssa-824503)

A vulnerability was found in Siemens Tecnomatix Plant Simulation and classified as critical. This issue affects some unknown processing of the component WRL File Handler. The manipulation leads to out-of-bounds read. The identification of this vulnerability is CVE-2024-52574. The attack may be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-47533 | cobbler up to 3.2.2/3.3.6 utils.get_shared_secret improper authentication

A vulnerability was found in cobbler up to 3.2.2/3.3.6 and classified as very critical. Affected by this issue is the function utils.get_shared_secret. The manipulation leads to improper authentication. This vulnerability is handled as CVE-2024-47533. The attack may be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-0012 | Palo Alto Networks Cloud NGFW/PAN-OS/Prisma Access Management Web Interface missing authentication

A vulnerability has been found in Palo Alto Networks Cloud NGFW, PAN-OS and Prisma Access and classified as very critical. Affected by this vulnerability is an unknown functionality of the component Management Web Interface. The manipulation leads to missing authentication. This vulnerability is known as CVE-2024-0012. The attack can be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More
Loading