Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-11-08 CVE-2024-40239 Unspecified vulnerability in Hitbytes Life 17.5.0
An incorrect access control issue in Life: Personal Diary, Journal android app 17.5.0 allows a physically proximate attacker to escalate privileges via the fingerprint authentication function.
low complexity
hitbytes
6.8
2024-11-08 CVE-2024-40240 Unspecified vulnerability in Homeserve 3.3.4
An incorrect access control issue in HomeServe Home Repair' android app - 3.3.4 allows a physically proximate attacker to escalate privileges via the fingerprint authentication function.
low complexity
homeserve
6.8
2024-11-08 CVE-2024-51030 SQL Injection vulnerability in Oretnom23 CAB Management System 1.0
A SQL injection vulnerability in manage_client.php and view_cab.php of Sourcecodester Cab Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter, leading to unauthorized access and potential compromise of sensitive data within the database.
network
low complexity
oretnom23 CWE-89
6.5
2024-11-08 CVE-2024-51031 Cross-site Scripting vulnerability in Oretnom23 CAB Management System 1.0
A Cross-site Scripting (XSS) vulnerability in manage_account.php in Sourcecodester Cab Management System 1.0 allows remote authenticated users to inject arbitrary web scripts via the "First Name," "Middle Name," and "Last Name" fields.
network
low complexity
oretnom23 CWE-79
5.4
2024-11-08 CVE-2024-51032 Cross-site Scripting vulnerability in Oretnom23 Toll TAX Management System 1.0
A Cross-site Scripting (XSS) vulnerability in manage_recipient.php of Sourcecodester Toll Tax Management System 1.0 allows remote authenticated users to inject arbitrary web scripts via the "owner" input field.
network
low complexity
oretnom23 CWE-79
5.4
2024-11-08 CVE-2024-51152 Unrestricted Upload of File with Dangerous Type vulnerability in Alexstack Laravel CMS
File Upload vulnerability in Laravel CMS v.1.4.7 and before allows a remote attacker to execute arbitrary code via the shell.php a component.
network
low complexity
alexstack CWE-434
7.2
2024-11-08 CVE-2024-9841 Cross-site Scripting vulnerability in Microfocus Arcsight Management Center and Arcsight Platform
A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Management Center and ArcSight Platform.
network
low complexity
microfocus CWE-79
6.1
2024-11-08 CVE-2024-25431 Out-of-bounds Read vulnerability in Bytecodealliance Webassembly Micro Runtime
An issue in bytecodealliance wasm-micro-runtime before v.b3f728c and fixed in commit 06df58f allows a remote attacker to escalate privileges via a crafted file to the check_was_abi_compatibility function.
local
low complexity
bytecodealliance CWE-125
7.8
2024-11-08 CVE-2024-45763 OS Command Injection vulnerability in Dell Enterprise Sonic Distribution
Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability.
network
low complexity
dell CWE-78
7.2
2024-11-08 CVE-2024-50634 Unspecified vulnerability in Sbond Watcharr
A vulnerability in a weak JWT token in Watcharr v1.43.0 and below allows attackers to perform privilege escalation using a crafted JWT token.
network
low complexity
sbond
8.8