Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In December 2024
A local low-level user on the server machine with credentials to the running OAS services can create and execute a report with an rdlx file on the server system itself. Any code within the rdlx file of the report executes with SYSTEM privileges, resulting in privilege escalation.
CVSS Score
7.8
EPSS Score
0.0
Published
2024-12-06
A Reflected Cross Site Scripting (XSS) vulnerability was found in /covidtms/registered-user-testing.php in PHPGurukul COVID 19 Testing Management System 1.0 which allows remote attackers to execute arbitrary code via the regmobilenumber parameter.
CVSS Score
6.1
EPSS Score
0.001
Published
2024-12-06
liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. A correctness error has been identified in the reference implementation of the HQC key encapsulation mechanism. Due to an indexing error, part of the secret key is incorrectly treated as non-secret data. This results in an incorrect shared secret value being returned when the decapsulation function is called with a malformed ciphertext. This vulnerability is fixed in 0.12.0.
CVSS Score
7.4
EPSS Score
0.001
Published
2024-12-06
A cross-site scripting (XSS) vulnerability in OroPlatform CMS v5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search parameter.
CVSS Score
6.1
EPSS Score
0.011
Published
2024-12-06
phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Prior to 4.0.0, phpMyFAQ exposes the database (ie postgreSQL) server's credential when connection to DB fails. This vulnerability is fixed in 4.0.0.
CVSS Score
8.6
EPSS Score
0.002
Published
2024-12-06
HCL Launch stores potentially sensitive information in log files that could be read by a local user with access to HTTP request logs.
CVSS Score
6.2
EPSS Score
0.0
Published
2024-12-06
A flaw was found in Rustls 0.23.13 and related APIs. This vulnerability allows denial of service (panic) via a fragmented TLS ClientHello message.
CVSS Score
5.3
EPSS Score
0.009
Published
2024-12-06
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visualmodo Borderless allows Cross-Site Scripting (XSS).This issue affects Borderless: from n/a through 1.5.8.
CVSS Score
5.9
EPSS Score
0.0
Published
2024-12-06
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor alam Magical Addons For Elementor allows Stored XSS.This issue affects Magical Addons For Elementor: from n/a through 1.2.6.
CVSS Score
6.5
EPSS Score
0.001
Published
2024-12-06
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite allows DOM-Based XSS.This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through 5.6.14.
CVSS Score
6.5
EPSS Score
0.001
Published
2024-12-06


Contact Us

Shodan ® - All rights reserved