Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-10-22 CVE-2024-49210 Cross-site Scripting vulnerability in Archerirm Archer
Reflected XSS was discovered in an iView List Archer Platform UX page in Archer Platform 6.x before version 2024.09.
network
low complexity
archerirm CWE-79
6.1
2024-10-22 CVE-2024-49211 Cross-site Scripting vulnerability in Archerirm Archer
Reflected XSS was discovered in a Dashboard Listing Archer Platform UX page in Archer Platform 6.x before version 2024.08.
network
low complexity
archerirm CWE-79
6.1
2024-10-22 CVE-2022-23861 Cross-site Scripting vulnerability in Ysoft Safeq 6.0
Multiple Stored Cross-Site Scripting vulnerabilities were discovered in Y Soft SAFEQ 6 Build 53.
network
low complexity
ysoft CWE-79
5.4
2024-10-22 CVE-2022-23862 Missing Authentication for Critical Function vulnerability in Ysoft Safeq 6.0
A Local Privilege Escalation issue was discovered in Y Soft SAFEQ 6 Build 53.
local
low complexity
ysoft CWE-306
7.8
2024-10-22 CVE-2024-46240 Cross-site Scripting vulnerability in O-Dyn Collabtive 3.1
Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under action=system and the company/contact parameters under action=addcust within admin.php file.
network
low complexity
o-dyn CWE-79
4.8
2024-10-22 CVE-2024-47819 Cross-site Scripting vulnerability in Umbraco CMS
Umbraco, a free and open source .NET content management system, has a cross-site scripting vulnerability starting in version 14.0.0 and prior to versions 14.3.1 and 15.0.0.
network
low complexity
umbraco CWE-79
8.7
2024-10-22 CVE-2024-48605 Uncontrolled Search Path Element vulnerability in Helakuru 1.1
An issue in Helakuru Desktop Application v1.1 allows a local attacker to execute arbitrary code via the lack of proper validation of the wow64log.dll file.
local
low complexity
helakuru CWE-427
7.8
2024-10-22 CVE-2024-48925 Incorrect Authorization vulnerability in Umbraco CMS
Umbraco, a free and open source .NET content management system, has an improper access control issue starting in version 14.0.0 and prior to version 14.3.0.
network
low complexity
umbraco CWE-863
6.5
2024-10-22 CVE-2024-48926 Insufficient Session Expiration vulnerability in Umbraco CMS
Umbraco, a free and open source .NET content management system, has an insufficient session expiration issue in versions on the 13.x branch prior to 13.5.2, 10.x prior to 10.8.7, and 8.x prior to 8.18.15.
network
high complexity
umbraco CWE-613
3.1
2024-10-22 CVE-2024-48927 Cross-site Scripting vulnerability in Umbraco CMS
Umbraco, a free and open source .NET content management system, has a remote code execution issue in versions on the 13.x branch prior to 13.5.2, 10.x prior to 10.8.7, and 8.x prior to 8.18.15.
network
low complexity
umbraco CWE-79
4.6