Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In August 2024
eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport.
CVSS Score
9.8
EPSS Score
0.102
Published
2024-08-20
The stripImages and stripIframes methods didn't properly process inputs, leading to XSS vectors.
CVSS Score
6.1
EPSS Score
0.001
Published
2024-08-20
SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_editplayer.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the vulnerability to execute arbitrary commands and gain system privileges.
CVSS Score
6.7
EPSS Score
0.001
Published
2024-08-20
Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not..
CVSS Score
6.1
EPSS Score
0.0
Published
2024-08-20
The pagination class includes arbitrary parameters in links, leading to cache poisoning attack vectors.
CVSS Score
9.1
EPSS Score
0.0
Published
2024-08-20
The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.
CVSS Score
6.1
EPSS Score
0.001
Published
2024-08-20
Improper Access Controls allows backend users to overwrite their username when disallowed.
CVSS Score
7.5
EPSS Score
0.0
Published
2024-08-20
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. A user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. This vulnerability is fixed in 1.14.2.
CVSS Score
8.8
EPSS Score
0.019
Published
2024-08-20
Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information. This security vulnerability is present in Ghost v4.46.0-v5.89.4. v5.89.5 contains a fix for this issue.
CVSS Score
6.5
EPSS Score
0.005
Published
2024-08-20
An issue in apollocongif apollo v.2.2.0 allows a remote attacker to obtain sensitive information via a crafted request.
CVSS Score
7.5
EPSS Score
0.003
Published
2024-08-20


Contact Us

Shodan ® - All rights reserved