In WordPress version 6.5.5 a medium severity vulnerability CVE-2024-6306 was detected. This vulnerability allows attackers to include arbitrary HTML Files on sites running Windows. There is no fix for this yet. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-6306/.
Read more CMSIn Ghost all versions through 5.85.1 a low severity vulnerability CVE-2024-34451 was detected. This flaw lets hackers bypass login attempt limits using multiple fake headers, but it can be avoided by setting up a reverse proxy to only accept trusted headers. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-34451/.
Read more CMSIn the Dolibarr version 19.0.1 a low severity vulnerability CVE-2024-37821 was detected. This vulnerability allows attackers to execute arbitrary code via uploading a crafted SQL file. There is no fix to this yet. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-37821/.
Read more ERPIn SuiteCRM versions 7.14.4 and 8.6.1 a medium severity vulnerability CVE-2024-36414 was detected. This vulnerability allows attackers to perform a server-side request forgery attack. To address this issue, users must install the fix in the versions 7.14.4 and 8.6.1. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-36414/.
Read more CRMIn SuiteCRM prior to versions 7.14.4 and 8.6.1 a medium severity vulnerability CVE-2024-36413 was detected. A weakness in the import module error view allows XSS attacks due to improper input sanitization. To address this issue, users should update SuiteCRM to versions 7.14.4 or 8.6.1. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-36413.
Read more CRMIn SuiteCRM versions prior to 7.14.4 and prior to 8.6.1 a high severity vulnerability CVE-2024-36415 was detected. This flaw in the product’s file upload system allows attackers to upload harmful files that can be executed, potentially compromising the system. This issue was resolved in versions 7.14.4 and 8.6.1. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-36415/.
Read more CRMIn SuiteCRM versions 7.14.4 and 8.6.1 a medium severity vulnerability CVE-2024-36407 was detected. An attacker can reset your password without accessing it, which can be annoying, and this only happens if certain password reset features are enabled and the system uses the outdated PHP 7 version. To address this issue, users should update SuiteCRM to versions 7.14.4 and 8.6.1. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-36407/.
In SuiteCRM prior to versions 7.14.4 and 8.6.1 a high severity vulnerability CVE-2024-36409 was detected. Poor input validation in the Tree data entry point allows SQL Injection because it doesn’t properly clean user input. This means that when the input is passed to other parts of the system, it can change the intended commands. To address this issue, users should update SuiteCRM to versions 7.14.4 or 8.6.1. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-36409.
Read more CRMIn SuiteCRM versions 7.14.4 and 8.6.1 a critical severity vulnerability CVE-2024-36412 was detected. This vulnerability allows attackers to use SQL injection attacks. To address this issue, users must install the fix in the versions 7.14.4 and 8.6.1. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-36412/.
Read more CRM