CVE-2024-26574
https://notcve.org/view.php?id=CVE-2024-26574
Insecure Permissions vulnerability in Wondershare Filmora v.13.0.51 allows a local attacker to execute arbitrary code via a crafted script to the WSNativePushService.exe La vulnerabilidad de permisos inseguros en Wondershare Filmora v.13.0.51 permite a un atacante local ejecutar código arbitrario a través de un script manipulado en WSNativePushService.exe • https://github.com/Alaatk/CVE-2024-26574 https://filmora.wondershare.com https://github.com/Alaatk/CVE-2024-26574/tree/main • CWE-276: Incorrect Default Permissions •
CVE-2024-3431 – EyouCMS Backend deserialization
https://notcve.org/view.php?id=CVE-2024-3431
This vulnerability affects unknown code of the file /login.php? • https://github.com/3309899621/CVE-2024-34310 https://github.com/vincentscode/CVE-2024-34313 https://github.com/vincentscode/CVE-2024-34312 https://terrific-street-3d0.notion.site/EYOUCMS-v1-6-5-RCE-7fe12e91a9b249e88e6ab36446b5ba22 https://vuldb.com/? • CWE-502: Deserialization of Untrusted Data •
CVE-2024-25029 – IBM Personal Communications code execution
https://notcve.org/view.php?id=CVE-2024-25029
IBM Personal Communications 14.0.6 through 15.0.1 includes a Windows service that is vulnerable to remote code execution (RCE) and local privilege escalation (LPE). ... IBM Personal Communications 14.0.6 a 15.0.1 incluye un servicio de Windows que es vulnerable a la ejecución remota de código (RCE) y a la escalada de privilegios local (LPE). • https://exchange.xforce.ibmcloud.com/vulnerabilities/281619 https://www.ibm.com/support/pages/node/7147672 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2023-25493
https://notcve.org/view.php?id=CVE-2023-25493
A potential vulnerability was reported in the BIOS update tool driver for some Desktop, Smart Edge, Smart Office, and ThinkStation products that could allow a local user with elevated privileges to execute arbitrary code. • https://support.lenovo.com/us/en/product_security/LEN-141775 • CWE-287: Improper Authentication CWE-306: Missing Authentication for Critical Function •
CVE-2024-30923 – DerbyNet 9.0 print/render/racer.inc SQL Injection
https://notcve.org/view.php?id=CVE-2024-30923
SQL Injection vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the where Clause in Racer Document Rendering Vulnerabilidad de inyección SQL en DerbyNet v9.0 y anteriores permite a un atacante remoto ejecutar código arbitrario a través de la cláusula donde en Racer Document Rendering DerbyNet 9.0 suffers from a remote SQL injection vulnerability in print/render/racer.inc. • https://chocapikk.com/posts/2024/derbynet-vulnerabilities • CWE-94: Improper Control of Generation of Code ('Code Injection') •