| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-33048 | Hig | 0.49 | 7.5 | 0.00 | Sep 2, 2024 | Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame. | ||
| CVE-2024-33047 | Hig | 0.55 | 8.4 | 0.00 | Sep 2, 2024 | Memory corruption when the captureRead QDCM command is invoked from user-space. | ||
| CVE-2024-33045 | Hig | 0.55 | 8.4 | 0.00 | Sep 2, 2024 | Memory corruption when BTFM client sends new messages over Slimbus to ADSP. | ||
| CVE-2024-33042 | Hig | 0.51 | 7.8 | 0.00 | Sep 2, 2024 | Memory corruption when Alternative Frequency offset value is set to 255. | ||
| CVE-2024-33038 | Hig | 0.51 | 7.8 | 0.00 | Sep 2, 2024 | Memory corruption while passing untrusted/corrupted pointers from DSP to EVA. | ||
| CVE-2024-33035 | Hig | 0.55 | 8.4 | 0.00 | Sep 2, 2024 | Memory corruption while calculating total metadata size when a very high reserved size is requested by gralloc clients. | ||
| CVE-2024-23365 | Hig | 0.55 | 8.4 | 0.00 | Sep 2, 2024 | Memory corruption while releasing shared resources in MinkSocket listener thread. | ||
| CVE-2024-23364 | Hig | 0.49 | 7.5 | 0.00 | Sep 2, 2024 | Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Element (IE) of a beacon frame that is received from over-the-air (OTA). | ||
| CVE-2024-23362 | Hig | 0.46 | 7.1 | 0.00 | Sep 2, 2024 | Cryptographic issue while parsing RSA keys in COBR format. | ||
| CVE-2024-23359 | Hig | 0.53 | 8.2 | 0.00 | Sep 2, 2024 | Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network. | ||
| CVE-2024-23358 | Hig | 0.49 | 7.5 | 0.00 | Sep 2, 2024 | Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem. | ||
| CVE-2024-7871 | Hig | 0.57 | 8.8 | 0.01 | Sep 2, 2024 | SQL Injection in online dictionary function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the word parameter. | ||
| CVE-2024-43776 | Hig | 0.57 | 8.8 | 0.00 | Sep 2, 2024 | SQL Injection in mock exam function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the qlevel parameter. | ||
| CVE-2024-43775 | Hig | 0.57 | 8.8 | 0.00 | Sep 2, 2024 | SQL Injection in search course titles function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the search parameter. | ||
| CVE-2024-43774 | Hig | 0.57 | 8.8 | 0.00 | Sep 2, 2024 | SQL Injection in download personal learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the uid parameter. | ||
| CVE-2024-41160 | Hig | 0.57 | 8.8 | 0.00 | Sep 2, 2024 | in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free. | ||
| CVE-2024-41157 | Hig | 0.57 | 8.8 | 0.00 | Sep 2, 2024 | in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free. | ||
| CVE-2024-39816 | Hig | 0.55 | 8.4 | 0.00 | Sep 2, 2024 | in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. | ||
| CVE-2024-38386 | Hig | 0.55 | 8.4 | 0.00 | Sep 2, 2024 | in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. | ||
| CVE-2024-20089 | Hig | 0.49 | 7.5 | 0.00 | Sep 2, 2024 | In wlan, there is a possible denial of service due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08861558; Issue ID: MSV-1526. | ||
| CVE-2024-8368 | Hig | 0.48 | 7.3 | 0.01 | Sep 1, 2024 | A vulnerability was found in code-projects Hospital Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file index.php of the component Login. The manipulation of the argument username leads to sql injection. The… | ||
| CVE-2024-44946 | Hig | 0.51 | 7.8 | 0.01 | Aug 31, 2024 | In the Linux kernel, the following vulnerability has been resolved: kcm: Serialise kcm_sendmsg() for the same socket. syzkaller reported UAF in kcm_release(). [0] The scenario is 1. Thread A builds a skb with MSG_MORE and sets kcm->seq_skb. 2. Thread A resumes building… | ||
| CVE-2024-7717 | Hig | 0.57 | 8.8 | 0.01 | Aug 31, 2024 | The WP Events Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all versions up to, and including, 2.1.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | ||
| CVE-2024-44945 | Hig | 0.46 | 7.1 | 0.00 | Aug 31, 2024 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink: Initialise extack before use in ACKs Add missing extack initialisation when ACKing BATCH_BEGIN and BATCH_END. | ||
| CVE-2024-7435 | Hig | 0.57 | 8.8 | 0.01 | Aug 31, 2024 | The Attire theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known… | ||
| CVE-2024-39747 | Hig | 0.53 | 8.1 | 0.01 | Aug 31, 2024 | IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses default credentials for potentially critical functionality. | ||
| CVE-2024-6586 | Hig | 0.41 | 7.3 | 0.02 | Aug 30, 2024 | Lightdash version 0.1024.6 allows users with the necessary permissions, such as Administrator or Editor, to create and share dashboards. A dashboard that contains HTML elements which point to a threat actor controlled source can trigger an SSRF request when exported, via a POST… | ||
| CVE-2024-38868 | Hig | 0.49 | 7.6 | 0.01 | Aug 30, 2024 | Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability while isolating the devices.This issue affects Endpoint Central: before 11.3.2406.08 and before 11.3.2400.15 | ||
| CVE-2024-6204 | Hig | 0.54 | 8.3 | 0.02 | Aug 30, 2024 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5715 are vulnerable to SQL Injection in the reports module. | ||
| CVE-2024-8343 | Hig | 0.48 | 7.3 | 0.01 | Aug 30, 2024 | A vulnerability, which was classified as critical, was found in SourceCodester Sentiment Based Movie Rating System 1.0. Affected is an unknown function of the file /classes/Users.php?f=save_client of the component User Registration Handler. The manipulation of the argument email… | ||
| CVE-2024-44916 | Hig | 0.47 | 7.2 | 0.01 | Aug 30, 2024 | Vulnerability in admin_ip.php in Seacms v13.1, when action=set, allows attackers to control IP parameters that are written to the data/admin/ip.php file and could result in arbitrary command execution. | ||
| CVE-2024-8340 | Hig | 0.48 | 7.3 | 0.01 | Aug 30, 2024 | A vulnerability classified as critical has been found in SourceCodester Electric Billing Management System 1.0. This affects an unknown part of the file /Actions.php?a=login. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack… | ||
| CVE-2024-8252 | Hig | 0.57 | 8.8 | 0.03 | Aug 30, 2024 | The Clean Login plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.14.5 via the 'template' attribute of the clean-login-register shortcode. This makes it possible for authenticated attackers, with Contributor-level access and… | ||
| CVE-2024-2694 | Hig | 0.57 | 8.8 | 0.01 | Aug 30, 2024 | The Betheme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 27.5.6 via deserialization of untrusted input of the 'mfn-page-items' post meta value. This makes it possible for authenticated attackers, with contributor-level access… | ||
| CVE-2024-5784 | Hig | 0.46 | 7.1 | 0.00 | Aug 30, 2024 | The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized administrative actions execution due to a missing capability checks on multiple functions like treport_quiz_atttempt_delete and tutor_gc_class_action in all versions up to, and including, 2.7.2. This makes it… | ||
| CVE-2024-8330 | Hig | 0.57 | 8.8 | 0.01 | Aug 30, 2024 | 6SHR system from Gether Technology does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload web shell scripts and use them to execute arbitrary system commands on the server. | ||
| CVE-2024-8329 | Hig | 0.57 | 8.8 | 0.01 | Aug 30, 2024 | 6SHR system from Gether Technology does not properly validate the specific page parameter, allowing remote attackers with regular privilege to inject SQL command to read, modify, and delete database contents. | ||
| CVE-2024-8327 | Hig | 0.57 | 8.8 | 0.01 | Aug 30, 2024 | Easy test Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with regular privilege to inject arbitrary SQL commands to read, modify, and delete database contents. | ||
| CVE-2024-45490 | Hig | 0.49 | 7.5 | 0.02 | Aug 30, 2024 | An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer. | ||
| CVE-2024-8234 | Hig | 0.49 | 7.5 | 0.04 | Aug 30, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the functions formSysCmd(), formUpgradeCert(), and formDelcert() in the Zyxel NWA1100-N firmware version 1.00(AACE.1)C0 could allow an unauthenticated attacker to execute some OS commands to access system files… | ||
| CVE-2024-6672 | Hig | 0.57 | 8.8 | 0.01 | Aug 29, 2024 | In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an authenticated low-privileged attacker to achieve privilege escalation by modifying a privileged user's password. | ||
| CVE-2024-34019 | Hig | 0.47 | 7.3 | 0.00 | Aug 29, 2024 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before build 4569. | ||
| CVE-2024-34017 | Hig | 0.47 | 7.3 | 0.00 | Aug 29, 2024 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before build 4569. | ||
| CVE-2024-43921 | Hig | 0.46 | 7.1 | 0.00 | Aug 29, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Magic Post Thumbnail allows Reflected XSS.This issue affects Magic Post Thumbnail: from n/a through 5.2.9. | ||
| CVE-2024-43963 | Hig | 0.46 | 7.1 | 0.00 | Aug 29, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WaspThemes YellowPencil Visual CSS Style Editor allows Reflected XSS.This issue affects YellowPencil Visual CSS Style Editor: from n/a through 7.6.1. | ||
| CVE-2024-43958 | Hig | 0.46 | 7.1 | 0.00 | Aug 29, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gianni Porto IntoTheDark allows Reflected XSS.This issue affects IntoTheDark: from n/a through 1.0.5. | ||
| CVE-2024-43950 | Hig | 0.46 | 7.1 | 0.00 | Aug 29, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Nextbricks Brickscore allows Stored XSS.This issue affects Brickscore: from n/a through 1.4.2.5. | ||
| CVE-2024-43948 | Hig | 0.46 | 7.1 | 0.00 | Aug 29, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dinesh Karki WP Armour Extended.This issue affects WP Armour Extended: from n/a through 1.26. | ||
| CVE-2024-43926 | Hig | 0.46 | 7.1 | 0.00 | Aug 29, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Beaver Builder Team Beaver Builder allows Reflected XSS.This issue affects Beaver Builder: from n/a through 2.8.3.2. | ||
| CVE-2024-43804 | Hig | 0.57 | 8.8 | 0.03 | Aug 29, 2024 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. An OS Command Injection vulnerability allows any authenticated user on the application to execute arbitrary code on the web application server via port scanning functionality. User-supplied… |
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when the captureRead QDCM command is invoked from user-space.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when BTFM client sends new messages over Slimbus to ADSP.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when Alternative Frequency offset value is set to 255.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while passing untrusted/corrupted pointers from DSP to EVA.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while calculating total metadata size when a very high reserved size is requested by gralloc clients.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while releasing shared resources in MinkSocket listener thread.
- risk 0.49cvss 7.5epss 0.00
Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Element (IE) of a beacon frame that is received from over-the-air (OTA).
- risk 0.46cvss 7.1epss 0.00
Cryptographic issue while parsing RSA keys in COBR format.
- risk 0.53cvss 8.2epss 0.00
Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.
- risk 0.49cvss 7.5epss 0.00
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem.
- risk 0.57cvss 8.8epss 0.01
SQL Injection in online dictionary function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the word parameter.
- risk 0.57cvss 8.8epss 0.00
SQL Injection in mock exam function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the qlevel parameter.
- risk 0.57cvss 8.8epss 0.00
SQL Injection in search course titles function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the search parameter.
- risk 0.57cvss 8.8epss 0.00
SQL Injection in download personal learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the uid parameter.
- risk 0.57cvss 8.8epss 0.00
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free.
- risk 0.57cvss 8.8epss 0.00
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free.
- risk 0.55cvss 8.4epss 0.00
in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write.
- risk 0.55cvss 8.4epss 0.00
in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write.
- risk 0.49cvss 7.5epss 0.00
In wlan, there is a possible denial of service due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08861558; Issue ID: MSV-1526.
- risk 0.48cvss 7.3epss 0.01
A vulnerability was found in code-projects Hospital Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file index.php of the component Login. The manipulation of the argument username leads to sql injection. The…
- risk 0.51cvss 7.8epss 0.01
In the Linux kernel, the following vulnerability has been resolved: kcm: Serialise kcm_sendmsg() for the same socket. syzkaller reported UAF in kcm_release(). [0] The scenario is 1. Thread A builds a skb with MSG_MORE and sets kcm->seq_skb. 2. Thread A resumes building…
- risk 0.57cvss 8.8epss 0.01
The WP Events Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all versions up to, and including, 2.1.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
- risk 0.46cvss 7.1epss 0.00
In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink: Initialise extack before use in ACKs Add missing extack initialisation when ACKing BATCH_BEGIN and BATCH_END.
- risk 0.57cvss 8.8epss 0.01
The Attire theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known…
- risk 0.53cvss 8.1epss 0.01
IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses default credentials for potentially critical functionality.
- risk 0.41cvss 7.3epss 0.02
Lightdash version 0.1024.6 allows users with the necessary permissions, such as Administrator or Editor, to create and share dashboards. A dashboard that contains HTML elements which point to a threat actor controlled source can trigger an SSRF request when exported, via a POST…
- risk 0.49cvss 7.6epss 0.01
Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability while isolating the devices.This issue affects Endpoint Central: before 11.3.2406.08 and before 11.3.2400.15
- risk 0.54cvss 8.3epss 0.02
Zohocorp ManageEngine Exchange Reporter Plus versions before 5715 are vulnerable to SQL Injection in the reports module.
- risk 0.48cvss 7.3epss 0.01
A vulnerability, which was classified as critical, was found in SourceCodester Sentiment Based Movie Rating System 1.0. Affected is an unknown function of the file /classes/Users.php?f=save_client of the component User Registration Handler. The manipulation of the argument email…
- risk 0.47cvss 7.2epss 0.01
Vulnerability in admin_ip.php in Seacms v13.1, when action=set, allows attackers to control IP parameters that are written to the data/admin/ip.php file and could result in arbitrary command execution.
- risk 0.48cvss 7.3epss 0.01
A vulnerability classified as critical has been found in SourceCodester Electric Billing Management System 1.0. This affects an unknown part of the file /Actions.php?a=login. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack…
- risk 0.57cvss 8.8epss 0.03
The Clean Login plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.14.5 via the 'template' attribute of the clean-login-register shortcode. This makes it possible for authenticated attackers, with Contributor-level access and…
- risk 0.57cvss 8.8epss 0.01
The Betheme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 27.5.6 via deserialization of untrusted input of the 'mfn-page-items' post meta value. This makes it possible for authenticated attackers, with contributor-level access…
- risk 0.46cvss 7.1epss 0.00
The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized administrative actions execution due to a missing capability checks on multiple functions like treport_quiz_atttempt_delete and tutor_gc_class_action in all versions up to, and including, 2.7.2. This makes it…
- risk 0.57cvss 8.8epss 0.01
6SHR system from Gether Technology does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload web shell scripts and use them to execute arbitrary system commands on the server.
- risk 0.57cvss 8.8epss 0.01
6SHR system from Gether Technology does not properly validate the specific page parameter, allowing remote attackers with regular privilege to inject SQL command to read, modify, and delete database contents.
- risk 0.57cvss 8.8epss 0.01
Easy test Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with regular privilege to inject arbitrary SQL commands to read, modify, and delete database contents.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.
- risk 0.49cvss 7.5epss 0.04
** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the functions formSysCmd(), formUpgradeCert(), and formDelcert() in the Zyxel NWA1100-N firmware version 1.00(AACE.1)C0 could allow an unauthenticated attacker to execute some OS commands to access system files…
- risk 0.57cvss 8.8epss 0.01
In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an authenticated low-privileged attacker to achieve privilege escalation by modifying a privileged user's password.
- risk 0.47cvss 7.3epss 0.00
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before build 4569.
- risk 0.47cvss 7.3epss 0.00
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before build 4569.
- risk 0.46cvss 7.1epss 0.00
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Magic Post Thumbnail allows Reflected XSS.This issue affects Magic Post Thumbnail: from n/a through 5.2.9.
- risk 0.46cvss 7.1epss 0.00
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WaspThemes YellowPencil Visual CSS Style Editor allows Reflected XSS.This issue affects YellowPencil Visual CSS Style Editor: from n/a through 7.6.1.
- risk 0.46cvss 7.1epss 0.00
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gianni Porto IntoTheDark allows Reflected XSS.This issue affects IntoTheDark: from n/a through 1.0.5.
- risk 0.46cvss 7.1epss 0.00
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Nextbricks Brickscore allows Stored XSS.This issue affects Brickscore: from n/a through 1.4.2.5.
- risk 0.46cvss 7.1epss 0.00
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dinesh Karki WP Armour Extended.This issue affects WP Armour Extended: from n/a through 1.26.
- risk 0.46cvss 7.1epss 0.00
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Beaver Builder Team Beaver Builder allows Reflected XSS.This issue affects Beaver Builder: from n/a through 2.8.3.2.
- risk 0.57cvss 8.8epss 0.03
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. An OS Command Injection vulnerability allows any authenticated user on the application to execute arbitrary code on the web application server via port scanning functionality. User-supplied…