Category: CVE

CVE-2024-50849 | WordServer 11.8.2 Rules cross site scripting

A vulnerability, which was classified as problematic, has been found in WordServer 11.8.2. This issue affects some unknown processing of the component Rules Handler. The manipulation leads to cross site scripting. The identification of this vulnerability is CVE-2024-50849. The attack may be initiated remotely. There is no exploit...

Read More

CVE-2024-48294 | Wondershare PDF Reader 1.0.9.2544 PDF File libPdfCore.dll null pointer dereference

A vulnerability classified as problematic has been found in Wondershare PDF Reader 1.0.9.2544. This affects an unknown part in the library libPdfCore.dll of the component PDF File Handler. The manipulation leads to null pointer dereference. This vulnerability is uniquely identified as CVE-2024-48294. It is possible to initiate the attack remotely. There is no exploit...

Read More

CVE-2024-48292 | QuickHeal Antivirus Pro/Total Security 24.0 wssrvc.exe Local Privilege Escalation

A vulnerability was found in QuickHeal Antivirus Pro and Total Security 24.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file wssrvc.exe. The manipulation leads to Local Privilege Escalation. This vulnerability is known as CVE-2024-48292. The attack needs to be approached locally. There is no exploit...

Read More

CVE-2023-49952 | Mastodon up to 4.1.16/4.2.8 HTTP Request Header allocation of resources (GHSA-c2r5-cfqr-c553)

A vulnerability was found in Mastodon up to 4.1.16/4.2.8. It has been classified as problematic. Affected is an unknown function of the component HTTP Request Header Handler. The manipulation leads to allocation of resources. This vulnerability is traded as CVE-2023-49952. It is possible to launch the attack remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-50848 | WorldServer 11.8.2 Object/Translation Memory Import xml external entity reference

A vulnerability was found in WorldServer 11.8.2 and classified as critical. This issue affects some unknown processing of the component Object/Translation Memory Import. The manipulation leads to xml external entity reference. The identification of this vulnerability is CVE-2024-50848. The attack may be initiated remotely. There is no exploit...

Read More

CVE-2024-50804 | Micro-star International MSI Center Pro 2.1.37.0 Device_DeviceID.dat.bak permission

A vulnerability has been found in Micro-star International MSI Center Pro 2.1.37.0 and classified as critical. This vulnerability affects unknown code of the file Device_DeviceID.dat.bak. The manipulation leads to permission issues. This vulnerability was named CVE-2024-50804. Local access is required to approach this attack. There is no exploit...

Read More

CVE-2024-52506 | Graylog2 Server up to 6.1.1 Reporting information disclosure

A vulnerability, which was classified as problematic, was found in Graylog2 Server up to 6.1.1. This affects an unknown part of the component Reporting. The manipulation leads to information disclosure. This vulnerability is uniquely identified as CVE-2024-52506. It is possible to initiate the attack remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-52583 | DefinetlyNotAI WesHacks schedule.html code download (93dfb83)

A vulnerability, which was classified as problematic, has been found in DefinetlyNotAI WesHacks. Affected by this issue is some unknown functionality of the file schedule.html. The manipulation leads to download of code without integrity check. This vulnerability is handled as CVE-2024-52583. The attack may be launched remotely. There is no exploit available. It is recommended to apply a patch to fix this...

Read More

CVE-2024-47873 | PHPOffice PhpSpreadsheet up to 1.29.3/2.1.2/2.3.1/3.3.x scan/findCharSet xml external entity reference (GHSA-jw4x-v69f-hh5w)

A vulnerability was found in PHPOffice PhpSpreadsheet up to 1.29.3/2.1.2/2.3.1/3.3.x and classified as critical. Affected by this issue is the function scan/findCharSet. The manipulation leads to xml external entity reference. This vulnerability is handled as CVE-2024-47873. The attack may be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-52424 | Suresh Kumar wp-login customizer Plugin up to 1.0 on WordPress cross-site request forgery

A vulnerability has been found in Suresh Kumar wp-login customizer Plugin up to 1.0 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. This vulnerability is known as CVE-2024-52424. The attack can be launched remotely. There is no exploit...

Read More
Loading