Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-02-05 CVE-2023-7216 Link Following vulnerability in multiple products
A path traversal vulnerability was found in the CPIO utility.
local
low complexity
gnu redhat CWE-59
5.3
2024-02-05 CVE-2024-24762 Unspecified vulnerability in Tiangolo Fastapi
`python-multipart` is a streaming multipart parser for Python.
network
low complexity
tiangolo
7.5
2024-02-05 CVE-2024-24768 Missing Encryption of Sensitive Data vulnerability in Fit2Cloud 1Panel 1.9.5
1Panel is an open source Linux server operation and maintenance management panel.
network
low complexity
fit2cloud CWE-311
7.5
2024-02-05 CVE-2024-23108 OS Command Injection vulnerability in Fortinet Fortisiem
An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 7.1.0 through 7.1.1 and 7.0.0 through 7.0.2 and 6.7.0 through 6.7.8 and 6.6.0 through 6.6.3 and 6.5.0 through 6.5.2 and 6.4.0 through 6.4.2 allows attacker to execute unauthorized code or commands via via crafted API requests.
network
low complexity
fortinet CWE-78
critical
9.8
2024-02-05 CVE-2024-23109 OS Command Injection vulnerability in Fortinet Fortisiem
An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 7.1.0 through 7.1.1 and 7.0.0 through 7.0.2 and 6.7.0 through 6.7.8 and 6.6.0 through 6.6.3 and 6.5.0 through 6.5.2 and 6.4.0 through 6.4.2 allows attacker to execute unauthorized code or commands via via crafted API requests.
network
low complexity
fortinet CWE-78
critical
9.8
2024-02-05 CVE-2024-1225 Deserialization of Untrusted Data vulnerability in Qibosoft Qibocms X1 1.0.6
A vulnerability classified as critical was found in QiboSoft QiboCMS X1 up to 1.0.6.
network
low complexity
qibosoft CWE-502
critical
9.8
2024-02-05 CVE-2023-5249 Use After Free vulnerability in ARM products
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improper memory processing operations to exploit a software race condition.
local
high complexity
arm CWE-416
7.0
2024-02-05 CVE-2023-5643 Out-of-bounds Write vulnerability in ARM products
Out-of-bounds Write vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations.
local
low complexity
arm CWE-787
7.8
2024-02-05 CVE-2021-4436 Unrestricted Upload of File with Dangerous Type vulnerability in Wp3Dprinting 3Dprint Lite
The 3DPrint Lite WordPress plugin before 1.9.1.5 does not have any authorisation and does not check the uploaded file in its p3dlite_handle_upload AJAX action , allowing unauthenticated users to upload arbitrary file to the web server.
network
low complexity
wp3dprinting CWE-434
critical
9.8
2024-02-05 CVE-2024-22386 NULL Pointer Dereference vulnerability in Linux Kernel
A race condition was found in the Linux kernel's drm/exynos device driver in exynos_drm_crtc_atomic_disable() function.
local
high complexity
linux CWE-476
4.7