Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-12-30 CVE-2024-13046 Out-of-bounds Write vulnerability in Ashlar Cobalt 1204.90
Ashlar-Vellum Cobalt CO File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability.
local
low complexity
ashlar CWE-787
7.8
2024-12-30 CVE-2024-13047 Type Confusion vulnerability in Ashlar Cobalt 1204.90
Ashlar-Vellum Cobalt CO File Parsing Type Confusion Remote Code Execution Vulnerability.
local
low complexity
ashlar CWE-843
7.8
2024-12-30 CVE-2024-13048 Out-of-bounds Write vulnerability in Ashlar Cobalt 1204.90
Ashlar-Vellum Cobalt XE File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability.
local
low complexity
ashlar CWE-787
7.8
2024-12-30 CVE-2024-13049 Type Confusion vulnerability in Ashlar Cobalt 1204.90
Ashlar-Vellum Cobalt XE File Parsing Type Confusion Remote Code Execution Vulnerability.
local
low complexity
ashlar CWE-843
7.8
2024-12-30 CVE-2024-13050 Out-of-bounds Write vulnerability in Ashlar Graphite 13.0.48
Ashlar-Vellum Graphite VC6 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability.
local
low complexity
ashlar CWE-787
7.8
2024-12-30 CVE-2024-13051 Out-of-bounds Write vulnerability in Ashlar Graphite 13.0.48
Ashlar-Vellum Graphite VC6 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability.
local
low complexity
ashlar CWE-787
7.8
2024-12-30 CVE-2024-54181 IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to execute arbitrary code.
network
low complexity
CWE-78
7.2
2024-12-30 CVE-2024-22063 Improper Neutralization of Formula Elements in a CSV File vulnerability in ZTE Zenic ONE R58
The ZENIC ONE R58 products by ZTE Corporation have a command injection vulnerability.
network
low complexity
zte CWE-1236
critical
9.0
2024-12-30 CVE-2024-13037 SQL Injection vulnerability in 1000Projects Attendance Tracking Management System 1.0
A vulnerability was found in 1000 Projects Attendance Tracking Management System 1.0.
network
low complexity
1000projects CWE-89
critical
9.8
2024-12-30 CVE-2024-13035 SQL Injection vulnerability in Code-Projects Chat System 1.0
A vulnerability has been found in code-projects Chat System 1.0 and classified as critical.
network
low complexity
code-projects CWE-89
critical
9.8