CVE-2024-10443
https://notcve.org/view.php?id=CVE-2024-10443
Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and Synology Photos before 1.6.2-0720 and 1.7.0-0795 allows remote attackers to execute arbitrary code via unspecified vectors. • https://www.synology.com/en-global/security/advisory/Synology_SA_24_18 https://www.synology.com/en-global/security/advisory/Synology_SA_24_19 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2024-50648
https://notcve.org/view.php?id=CVE-2024-50648
yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP files. • https://github.com/Yllxx03/CVE/blob/main/yshop_fileu_pload.md https://github.com/Yllxx03/CVE/tree/main/CVE-2024-50648 •
CVE-2024-50800
https://notcve.org/view.php?id=CVE-2024-50800
Cross Site Scripting vulnerability in M2000 Smart4Web before v.5.020241004 allows a remote attacker to execute arbitrary code via the error parameter in URL • https://github.com/Jellyfishxoxo/vulnerability-research/tree/main/CVE-2024-50800 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2024-50986
https://notcve.org/view.php?id=CVE-2024-50986
An issue in Clementine v.1.3.1 allows a local attacker to execute arbitrary code via a crafted DLL file. • https://github.com/clementine-player/Clementine https://github.com/riftsandroses/CVE-2024-50986 https://www.clementine-player.org •
CVE-2024-51141
https://notcve.org/view.php?id=CVE-2024-51141
An issue in TOTOLINK Bluetooth Wireless Adapter A600UB allows a local attacker to execute arbitrary code via the WifiAutoInstallDriver.exe and MSASN1.dll components. • https://infosecwriteups.com/dll-hijacking-in-totolink-a600ub-driver-installer-13787c4d97b4 • CWE-354: Improper Validation of Integrity Check Value •