CVE-2024-3914 – Microsoft Edge DOMArrayBuffer Use-After-Free Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2024-3914
Use after free in V8 in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. ... (Severidad de seguridad de Chrome: alta) This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Edge. ... An attacker can leverage this vulnerability to execute code in the context of the current process at low integrity. • https://chromereleases.googleblog.com/2024/04/stable-channel-update-for-desktop_16.html https://issues.chromium.org/issues/330759272 https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CWIVXXSVO5VB3NAZVFJ7CWVBN6W2735T https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IDLUD644WEWGOFKMZWC2K7Z4CQOKQYR7 https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M4PCXKCOVBUUU6GOSN46DCPI4HMER3PJ https://lists.fedoraproject.org/archives/list • CWE-416: Use After Free •
CVE-2024-32523 – WordPress Mailster plugin <= 4.0.6 - Unauthenticated Local File Inclusion vulnerability
https://notcve.org/view.php?id=CVE-2024-32523
This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included. • https://github.com/truonghuuphuc/CVE-2024-32523-Poc https://patchstack.com/database/vulnerability/mailster/wordpress-mailster-plugin-4-0-6-unauthenticated-local-file-inclusion-vulnerability?_s_id=cve • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE-98: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') •
CVE-2024-30567
https://notcve.org/view.php?id=CVE-2024-30567
An issue in JNT Telecom JNT Liftcom UMS V1.J Core Version JM-V15 allows a remote attacker to execute arbitrary code via the Network Troubleshooting functionality. • https://gist.github.com/s4fv4n/f0e8eccd0ce4bd1ac109fa2481c90ee6 • CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2024-31648
https://notcve.org/view.php?id=CVE-2024-31648
Cross Site Scripting (XSS) in Insurance Management System v1.0, allows remote attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category Name parameter at /core/new_category2. • https://github.com/Mohitkumar0786/CVE/blob/main/CVE-2024-31648.md • CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2020-22539
https://notcve.org/view.php?id=CVE-2020-22539
An arbitrary file upload vulnerability in the Add Category function of Codoforum v4.9 allows attackers to execute arbitrary code via uploading a crafted file. • https://gist.github.com/s4fv4n/320f536a684650c6948433de8d53713c • CWE-434: Unrestricted Upload of File with Dangerous Type •