Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In August 2024
SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_editplayer.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the vulnerability to execute arbitrary commands and gain system privileges.
CVSS Score
6.7
EPSS Score
0.001
Published
2024-08-20
Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not..
CVSS Score
6.1
EPSS Score
0.0
Published
2024-08-20
The pagination class includes arbitrary parameters in links, leading to cache poisoning attack vectors.
CVSS Score
9.1
EPSS Score
0.0
Published
2024-08-20
The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.
CVSS Score
6.1
EPSS Score
0.001
Published
2024-08-20
Improper Access Controls allows backend users to overwrite their username when disallowed.
CVSS Score
7.5
EPSS Score
0.0
Published
2024-08-20
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. A user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. This vulnerability is fixed in 1.14.2.
CVSS Score
8.8
EPSS Score
0.019
Published
2024-08-20
Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information. This security vulnerability is present in Ghost v4.46.0-v5.89.4. v5.89.5 contains a fix for this issue.
CVSS Score
6.5
EPSS Score
0.005
Published
2024-08-20
An issue in apollocongif apollo v.2.2.0 allows a remote attacker to obtain sensitive information via a crafted request.
CVSS Score
7.5
EPSS Score
0.003
Published
2024-08-20
Umbraco is an ASP.NET CMS. Some endpoints in the Management API can return stack trace information, even when Umbraco is not in debug mode. This vulnerability is fixed in 14.1.2.
CVSS Score
4.3
EPSS Score
0.005
Published
2024-08-20
Umbraco CMS is an ASP.NET CMS. An authenticated user can access a few unintended endpoints. This issue is fixed in 14.1.2.
CVSS Score
5.4
EPSS Score
0.004
Published
2024-08-20


Contact Us

Shodan ® - All rights reserved