Common Vulnerabilities and Exposures (CVE)

CVE-2024-5171

Sep 7, 2024 21:02:30 UTC

Integer overflow in libaom internal function img_alloc_helper can lead to heap buffer overflow. This function can be reached via 3 callers: * Calling aom_img_alloc() with a large value of the d_w, d_h, or align parameter may result in ...

CVE-2024-8564

Sep 7, 2024 20:31:03 UTC

A vulnerability was found in SourceCodester PHP CRUD 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /endpoint/update.php. The manipulation of the argument tbl_person_id/first_name/middle_name/last...

CVE-2024-8563

Sep 7, 2024 20:00:04 UTC

A vulnerability was found in SourceCodester PHP CRUD 1.0. It has been classified as problematic. This affects an unknown part of the file /endpoint/update.php. The manipulation of the argument first_name/middle_name/last_name leads to cross...

CVE-2024-8562

Sep 7, 2024 19:00:05 UTC

A vulnerability was found in SourceCodester PHP CRUD 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /endpoint/Add.php. The manipulation of the argument first_name/middle_name/last_name le...

CVE-2024-8561

Sep 7, 2024 18:31:03 UTC

A vulnerability has been found in SourceCodester PHP CRUD 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /endpoint/delete.php of the component Delete Person Handler. The manipulation o...

CVE-2024-8560

Sep 7, 2024 18:00:04 UTC

A vulnerability, which was classified as critical, was found in SourceCodester Simple Invoice Generator System 1.0. Affected is an unknown function of the file /save_invoice.php. The manipulation of the argument invoice_code/customer/cashie...

CVE-2024-8559

Sep 7, 2024 17:31:07 UTC

A vulnerability, which was classified as critical, has been found in SourceCodester Online Food Menu 1.0. This issue affects some unknown processing of the file /endpoint/delete-menu.php. The manipulation of the argument menu leads to sql i...

CVE-2024-38650

Sep 7, 2024 16:11:22 UTC

An authentication bypass vulnerability can allow a low privileged attacker to access the NTLM hash of service account on the VSPC server.

CVE-2024-42021

Sep 7, 2024 16:11:22 UTC

An improper access control vulnerability allows an attacker with valid access tokens to access saved credentials.

CVE-2024-40718

Sep 7, 2024 16:11:22 UTC

A server side request forgery vulnerability allows a low-privileged user to perform local privilege escalation through exploiting an SSRF vulnerability.

CVE-2024-42023

Sep 7, 2024 16:11:22 UTC

An improper access control vulnerability allows low-privileged users to execute code with Administrator privileges remotely.

CVE-2024-40714

Sep 7, 2024 16:11:22 UTC

An improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to intercept sensitive credentials during restore operations.

CVE-2024-42022

Sep 7, 2024 16:11:22 UTC

An incorrect permission assignment vulnerability allows an attacker to modify product configuration files.

CVE-2024-42024

Sep 7, 2024 16:11:22 UTC

A vulnerability that allows an attacker in possession of the Veeam ONE Agent service account credentials to perform remote code execution on the machine where the Veeam ONE Agent is installed.

CVE-2024-40709

Sep 7, 2024 16:11:22 UTC

A missing authorization vulnerability allows a local low-privileged user on the machine to escalate their privileges to root level.