Show filters
1,481 Total Results
Displaying 271-280 of 1,481
Sort by:
Attacker Value
Unknown
CVE-2024-38346
Disclosure Date: July 05, 2024 (last updated February 26, 2025)
The CloudStack cluster service runs on unauthenticated port (default 9090) that can be misused to run arbitrary commands on targeted hypervisors and CloudStack management server hosts. Some of these commands were found to have command injection vulnerabilities that can result in arbitrary code execution via agents on the hosts that may run as a privileged user. An attacker that can reach the cluster service on the unauthenticated port (default 9090), can exploit this to perform remote code execution on CloudStack managed hosts and result in complete compromise of the confidentiality, integrity, and availability of CloudStack managed infrastructure.
Users are recommended to restrict the network access to the cluster service port (default 9090) on a CloudStack management server host to only its peer CloudStack management server hosts. Users are recommended to upgrade to version 4.18.2.1, 4.19.0.2 or later, which addresses this issue.
0
Attacker Value
Unknown
CVE-2024-39932
Disclosure Date: July 04, 2024 (last updated February 26, 2025)
Gogs through 0.13.0 allows argument injection during the previewing of changes.
0
Attacker Value
Unknown
CVE-2024-39165
Disclosure Date: July 04, 2024 (last updated February 26, 2025)
QR/demoapp/qr_image.php in Asial JpGraph Professional through 4.2.6-pro allows remote attackers to execute arbitrary code via a PHP payload in the data parameter in conjunction with a .php file name in the filename parameter. This occurs because an unnecessary QR/demoapp folder.is shipped with the product.
0
Attacker Value
Unknown
CVE-2024-6507
Disclosure Date: July 04, 2024 (last updated February 26, 2025)
Command injection when ingesting a remote Kaggle dataset due to a lack of input sanitization in the ingest_kaggle() API
0
Attacker Value
Unknown
CVE-2024-33871
Disclosure Date: July 03, 2024 (last updated February 26, 2025)
An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution via a custom Driver library, exploitable via a crafted PostScript document. This occurs because the Driver parameter for opvp (and oprp) devices can have an arbitrary name for a dynamic library; this library is then loaded.
0
Attacker Value
Unknown
CVE-2024-39844
Disclosure Date: July 03, 2024 (last updated February 26, 2025)
In ZNC before 1.9.1, remote code execution can occur in modtcl via a KICK.
0
Attacker Value
Unknown
CVE-2024-25086
Disclosure Date: July 02, 2024 (last updated February 26, 2025)
Improper privilege management in Jungo WinDriver before 12.2.0 allows local attackers to escalate privileges and execute arbitrary code.
0
Attacker Value
Unknown
CVE-2024-39236
Disclosure Date: July 01, 2024 (last updated February 26, 2025)
Gradio v4.36.1 was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py. This vulnerability is triggered via a crafted input. NOTE: the supplier disputes this because the report is about a user attacking himself.
0
Attacker Value
Unknown
CVE-2024-6376
Disclosure Date: July 01, 2024 (last updated February 26, 2025)
MongoDB Compass may be susceptible to code injection due to insufficient sandbox protection settings with the usage of ejson shell parser in Compass' connection handling. This issue affects MongoDB Compass versions prior to version 1.42.2
0
Attacker Value
Unknown
CVE-2024-39017
Disclosure Date: July 01, 2024 (last updated February 26, 2025)
agreejs shared v0.0.1 was discovered to contain a prototype pollution via the function mergeInternalComponents. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
0