Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In April 2024
The Fancy Product Designer WordPress plugin before 6.1.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against unauthenticated and admin-level users
CVSS Score
6.3
EPSS Score
0.002
Published
2024-04-26
Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1, allows remote attackers to execute arbitrary code via a crafted payload to the Markup Sandbox feature.
CVSS Score
6.0
EPSS Score
0.006
Published
2024-04-26
Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via a crafted payload to the Batch-Issue Exam Tickets function.
CVSS Score
7.5
EPSS Score
0.021
Published
2024-04-26
cJSON v1.7.17 was discovered to contain a segmentation violation, which can trigger through the second parameter of function cJSON_SetValuestring at cJSON.c.
CVSS Score
7.6
EPSS Score
0.012
Published
2024-04-26
An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. The Backup Exec Deduplication Multi-threaded Streaming Agent can be leveraged to perform arbitrary file deletion on protected files.
CVSS Score
7.7
EPSS Score
0.001
Published
2024-04-26
An issue was discovered in Veritas NetBackup before 10.4. The Multi-Threaded Agent used in NetBackup can be leveraged to perform arbitrary file deletion on protected files.
CVSS Score
7.7
EPSS Score
0.0
Published
2024-04-26
An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. Improper access controls allow for DLL Hijacking in the Windows DLL Search path.
CVSS Score
7.8
EPSS Score
0.001
Published
2024-04-26
An issue was discovered in Zammad before 6.3.0. Users with customer access to a ticket could have accessed time accounting details of this ticket via the API. This data should be available only to agents.
CVSS Score
8.6
EPSS Score
0.002
Published
2024-04-26
An issue was discovered in Zammad before 6.3.0. An authenticated agent could perform a remote Denial of Service attack by calling an endpoint that accepts a generic method name, which was not properly sanitized against an allowlist.
CVSS Score
6.5
EPSS Score
0.008
Published
2024-04-26
An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to identify content. An attacker could try to brute force them to upload malicious content to article drafts they have no access to.
CVSS Score
9.1
EPSS Score
0.002
Published
2024-04-26


Contact Us

Shodan ® - All rights reserved