Show filters
1,481 Total Results
Displaying 271-280 of 1,481
Sort by:
Attacker Value
Unknown

CVE-2024-38346

Disclosure Date: July 05, 2024 (last updated February 26, 2025)
The CloudStack cluster service runs on unauthenticated port (default 9090) that can be misused to run arbitrary commands on targeted hypervisors and CloudStack management server hosts. Some of these commands were found to have command injection vulnerabilities that can result in arbitrary code execution via agents on the hosts that may run as a privileged user. An attacker that can reach the cluster service on the unauthenticated port (default 9090), can exploit this to perform remote code execution on CloudStack managed hosts and result in complete compromise of the confidentiality, integrity, and availability of CloudStack managed infrastructure. Users are recommended to restrict the network access to the cluster service port (default 9090) on a CloudStack management server host to only its peer CloudStack management server hosts. Users are recommended to upgrade to version 4.18.2.1, 4.19.0.2 or later, which addresses this issue.
Attacker Value
Unknown

CVE-2024-39932

Disclosure Date: July 04, 2024 (last updated February 26, 2025)
Gogs through 0.13.0 allows argument injection during the previewing of changes.
0
Attacker Value
Unknown

CVE-2024-39165

Disclosure Date: July 04, 2024 (last updated February 26, 2025)
QR/demoapp/qr_image.php in Asial JpGraph Professional through 4.2.6-pro allows remote attackers to execute arbitrary code via a PHP payload in the data parameter in conjunction with a .php file name in the filename parameter. This occurs because an unnecessary QR/demoapp folder.is shipped with the product.
0
Attacker Value
Unknown

CVE-2024-6507

Disclosure Date: July 04, 2024 (last updated February 26, 2025)
Command injection when ingesting a remote Kaggle dataset due to a lack of input sanitization in the ingest_kaggle() API
0
Attacker Value
Unknown

CVE-2024-33871

Disclosure Date: July 03, 2024 (last updated February 26, 2025)
An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution via a custom Driver library, exploitable via a crafted PostScript document. This occurs because the Driver parameter for opvp (and oprp) devices can have an arbitrary name for a dynamic library; this library is then loaded.
0
Attacker Value
Unknown

CVE-2024-39844

Disclosure Date: July 03, 2024 (last updated February 26, 2025)
In ZNC before 1.9.1, remote code execution can occur in modtcl via a KICK.
0
Attacker Value
Unknown

CVE-2024-25086

Disclosure Date: July 02, 2024 (last updated February 26, 2025)
Improper privilege management in Jungo WinDriver before 12.2.0 allows local attackers to escalate privileges and execute arbitrary code.
Attacker Value
Unknown

CVE-2024-39236

Disclosure Date: July 01, 2024 (last updated February 26, 2025)
Gradio v4.36.1 was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py. This vulnerability is triggered via a crafted input. NOTE: the supplier disputes this because the report is about a user attacking himself.
0
Attacker Value
Unknown

CVE-2024-6376

Disclosure Date: July 01, 2024 (last updated February 26, 2025)
MongoDB Compass may be susceptible to code injection due to insufficient sandbox protection settings with the usage of ejson shell parser in Compass' connection handling. This issue affects MongoDB Compass versions prior to version 1.42.2
Attacker Value
Unknown

CVE-2024-39017

Disclosure Date: July 01, 2024 (last updated February 26, 2025)
agreejs shared v0.0.1 was discovered to contain a prototype pollution via the function mergeInternalComponents. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
0