Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In October 2024
Authenticated RCE via Path Traversal
CVSS Score
7.6
EPSS Score
0.005
Published
2024-10-07
Authenticated RCE via Path Traversal
CVSS Score
7.6
EPSS Score
0.005
Published
2024-10-07
An issue was discovered in the m2m scaler driver in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850,and W920. A Use-After-Free in the mobile processor leads to privilege escalation.
CVSS Score
8.1
EPSS Score
0.01
Published
2024-10-07
BlueCMS 1.6 suffers from Arbitrary File Deletion via the file_name parameter in an /admin/database.php?act=del request.
CVSS Score
4.9
EPSS Score
0.003
Published
2024-10-07
D-Link COVR-2600R FW101b05 is vulnerable to Buffer Overflow. In the function sub_24E28, the HTTP_REFERER is obtained through an environment variable, and this field is controllable, allowing it to be used as the value for src.
CVSS Score
5.7
EPSS Score
0.042
Published
2024-10-07
RuoYi v4.7.9 and before has a security flaw that allows escaping from comments within the code generation feature, enabling the injection of malicious code.
CVSS Score
9.8
EPSS Score
0.005
Published
2024-10-07
itsourcecode Placement Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Full Name field in registration.php.
CVSS Score
6.1
EPSS Score
0.004
Published
2024-10-07
Cross Site Scripting vulnerability in LimeSurvey before 6.5.12+240611 allows a remote attacker to execute arbitrary code via a crafted script to the title and comment fields.
CVSS Score
6.1
EPSS Score
0.005
Published
2024-10-07
Cross Site Scripting vulnerability in LimeSurvey before 6.5.0+240319 allows a remote attacker to execute arbitrary code via a lack of input validation and output encoding in the Alert Widget's message component.
CVSS Score
6.1
EPSS Score
0.005
Published
2024-10-07
Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in /admin/contacts/organizations/edit/2.
CVSS Score
4.8
EPSS Score
0.004
Published
2024-10-07


Contact Us

Shodan ® - All rights reserved