Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-11-13 CVE-2024-23715 Out-of-bounds Write vulnerability in Google Android
In PMRWritePMPageList of pmr.c, there is a possible out of bounds write due to a logic error in the code.
local
low complexity
google CWE-787
7.8
2024-11-13 CVE-2024-43093 Unspecified vulnerability in Google Android
In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization.
local
low complexity
google
7.8
2024-11-13 CVE-2024-52291 Path Traversal vulnerability in Craftcms Craft CMS
Craft is a content management system (CMS).
network
low complexity
craftcms CWE-22
7.2
2024-11-13 CVE-2024-52292 Files or Directories Accessible to External Parties vulnerability in Craftcms Craft CMS
Craft is a content management system (CMS).
network
low complexity
craftcms CWE-552
6.5
2024-11-13 CVE-2024-11175 Cross-site Scripting vulnerability in Publiccms 5.202406.D
A vulnerability was found in Public CMS 5.202406.d and classified as problematic.
network
low complexity
publiccms CWE-79
4.8
2024-11-13 CVE-2024-50969 Cross-site Scripting vulnerability in Anisha Jonnys Liquor 1.0
A Reflected cross-site scripting (XSS) vulnerability in browse.php of Code-projects Jonnys Liquor 1.0 allows remote attackers to inject arbitrary web scripts or HTML via the search parameter.
network
low complexity
anisha CWE-79
6.1
2024-11-13 CVE-2024-50970 SQL Injection vulnerability in Nikoarroyocuraza Online Furniture Shopping Project 1.0
A SQL injection vulnerability in orderview1.php of Itsourcecode Online Furniture Shopping Project 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
network
low complexity
nikoarroyocuraza CWE-89
8.8
2024-11-13 CVE-2024-50971 SQL Injection vulnerability in Angeljudesuarez Construction Management System 1.0
A SQL injection vulnerability in print.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the map_id parameter.
network
low complexity
angeljudesuarez CWE-89
7.2
2024-11-13 CVE-2024-50972 SQL Injection vulnerability in Angeljudesuarez Construction Management System 1.0
A SQL injection vulnerability in printtool.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the borrow_id parameter.
network
low complexity
angeljudesuarez CWE-89
7.2
2024-11-13 CVE-2024-52293 Path Traversal vulnerability in Craftcms Craft CMS
Craft is a content management system (CMS).
network
low complexity
craftcms CWE-22
7.2