Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2024-11-18 CVE-2024-42385 Unspecified vulnerability in Cesanta Mongoose
Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bound memory write if the PEM certificate contains unexpected characters.
local
high complexity
cesanta
7.0
2024-11-18 CVE-2024-42386 Unspecified vulnerability in Cesanta Mongoose
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.
network
low complexity
cesanta
7.5
2024-11-18 CVE-2024-42392 Unspecified vulnerability in Cesanta Mongoose
Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an infinite loop bug if the input string contains unexpected characters.
network
low complexity
cesanta
7.5
2024-11-18 CVE-2024-41969 A low privileged remote attacker may modify the configuration of the CODESYS V3 service through a missing authentication vulnerability which could lead to full system access and/or DoS.
network
low complexity
CWE-306
8.8
2024-11-18 CVE-2024-48962 Code Injection vulnerability in Apache Ofbiz
Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.17. Users are recommended to upgrade to version 18.12.17, which fixes the issue.
network
low complexity
apache CWE-94
8.8
2024-11-18 CVE-2024-49574 SQL Injection vulnerability in Zohocorp Manageengine Adaudit Plus
Zohocorp ManageEngine ADAudit Plus versions below 8123 are vulnerable to SQL Injection in the reports module.
network
low complexity
zohocorp CWE-89
8.8
2024-11-18 CVE-2024-22067 Unspecified vulnerability in ZTE Nh8091 Firmware Znh8091V1.8
ZTE NH8091 product has an improper permission control vulnerability.
network
low complexity
zte
8.8
2024-11-17 CVE-2020-25720 A vulnerability was found in Samba where a delegated administrator with permission to create objects in Active Directory can write to all attributes of the newly created object, including security-sensitive attributes, even after the object's creation.
network
high complexity
CWE-264
7.5
2024-11-17 CVE-2024-0793 A flaw was found in kube-controller-manager.
network
low complexity
CWE-20
7.7
2024-11-15 CVE-2024-11262 Out-of-bounds Write vulnerability in Razormist Student Record Management System 1.0
A vulnerability has been found in SourceCodester Student Record Management System 1.0 and classified as critical.
local
low complexity
razormist CWE-787
7.8