Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-09-18 CVE-2024-43024 Cross-site Scripting vulnerability in RWS Multitrans
Multiple stored cross-site scripting (XSS) vulnerabilities in RWS MultiTrans v7.0.23324.2 and earlier allow attackers to execute arbitrary web scripts or HTML via a crafted payload.
network
low complexity
rws CWE-79
6.1
2024-09-18 CVE-2024-43025 Cross-site Scripting vulnerability in RWS Multitrans
An HTML injection vulnerability in RWS MultiTrans v7.0.23324.2 and earlier allows attackers to alter the HTML-layout and possibly execute a phishing attack via a crafted payload injected into a sent e-mail.
network
low complexity
rws CWE-79
6.1
2024-09-18 CVE-2024-34057 Classic Buffer Overflow vulnerability in multiple products
Triangle Microworks TMW IEC 61850 Client source code libraries before 12.2.0 lack a buffer size check when processing received messages.
network
low complexity
trianglemicroworks siemens CWE-120
7.5
2024-09-18 CVE-2024-8287 Improper Certificate Validation vulnerability in Canonical Anbox Cloud
Anbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the Anbox Stream Agent.
high complexity
canonical CWE-295
7.5
2024-09-18 CVE-2024-46986 Path Traversal vulnerability in Tuzitio Camaleon CMS
Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails.
network
low complexity
tuzitio CWE-22
critical
9.9
2024-09-18 CVE-2024-46987 Path Traversal vulnerability in Tuzitio Camaleon CMS
Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails.
network
low complexity
tuzitio CWE-22
7.7
2024-09-18 CVE-2024-46086 Cross-Site Request Forgery (CSRF) vulnerability in Frogcms Project Frogcms 0.9.5
FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/delete/123
network
low complexity
frogcms-project CWE-352
8.8
2024-09-18 CVE-2022-25774 Cross-site Scripting vulnerability in Acquia Mautic
Prior to the patched version, logged in users of Mautic are vulnerable to a self XSS vulnerability in the notifications within Mautic. Users could inject malicious code into the notification when saving Dashboards.
network
low complexity
acquia CWE-79
5.4
2024-09-18 CVE-2022-25775 SQL Injection vulnerability in Acquia Mautic
Prior to the patched version, logged in users of Mautic are vulnerable to an SQL injection vulnerability in the Reports bundle. The user could retrieve and alter data like sensitive data, login, and depending on database permission the attacker can manipulate file systems.
network
low complexity
acquia CWE-89
7.2
2024-09-18 CVE-2022-25776 Incorrect Default Permissions vulnerability in Acquia Mautic
Prior to the patched version, logged in users of Mautic are able to access areas of the application that they should be prevented from accessing. Users could potentially access sensitive data such as names and surnames, company names and stage names.
network
low complexity
acquia CWE-276
6.5