CVE-2024-7559 – File Manager Pro <= 8.3.7 - Authenticated (Subscriber+) Arbitrary File Upload
https://notcve.org/view.php?id=CVE-2024-7559
The File Manager Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and capability checks in the mk_file_folder_manager AJAX action in all versions up to, and including, 8.3.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. • https://filemanagerpro.io/file-manager-pro https://www.wordfence.com/threat-intel/vulnerabilities/id/f4b45791-4b85-4a2d-8019-1d438bd694cb?source=cve • CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2024-42599
https://notcve.org/view.php?id=CVE-2024-42599
SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_files.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the vulnerability to execute arbitrary commands and gain system privileges. • https://gitee.com/fushuling/cve/blob/master/CVE-2024-42599.md https://gitee.com/fushuling/cve/blob/master/SeaCMS%20V13%20admin_files.php%20code%20injection.md • CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2024-43033
https://notcve.org/view.php?id=CVE-2024-43033
JPress through 5.1.1 on Windows has an arbitrary file upload vulnerability that could cause arbitrary code execution via ::$DATA to AttachmentController, such as a .jsp::$DATA file to io.jpress.web.commons.controller.AttachmentController#upload. • https://cwe.mitre.org/data/definitions/69.html https://github.com/JPressProjects/jpress/issues/188 https://github.com/lazy-forever/CVE-Reference/tree/main/2024/43033 • CWE-69: Improper Handling of Windows ::DATA Alternate Data Stream •
CVE-2024-33656 – Memory Leak in SmmComuptrace Module
https://notcve.org/view.php?id=CVE-2024-33656
This could lead to privilege escalation, arbitrary code execution, and bypassing OS security mechanisms • https://9443417.fs1.hubspotusercontent-na1.net/hubfs/9443417/Security%20Advisories/2024/AMI-SA-2024003.pdf • CWE-269: Improper Privilege Management •
CVE-2024-40453
https://notcve.org/view.php?id=CVE-2024-40453
squirrellyjs squirrelly v9.0.0 and fixed in v.9.0.1 was discovered to contain a code injection vulnerability via the component options.varName. • https://github.com/squirrellyjs/squirrelly https://github.com/squirrellyjs/squirrelly/pull/262 https://samuzora.com/posts/cve-2024-40453 • CWE-94: Improper Control of Generation of Code ('Code Injection') •