
CVE-2024-4956
Sonatype Nexus Repository Manager 3 (LFI)

Sonatype Nexus Repository Manager 3 (LFI)

WordPress WPS Hide Login <1.9.1 - Information Disclosure

Check Point Security Gateway (LFI)

WordPress Contact Form 7 - Unrestricted File Upload

Microsoft FrontPage Extensions Check (shtml.dll)

Apache Superset - Authentication Bypass

phpMyAdmin <4.9.0 - Cross-Site Request Forgery

SpiderFlow Crawler Platform - Remote Code Execution

Joomla! Core SQL Injection

LearnDash LMS < 4.10.3 - Sensitive Information Exposure

Apache <= 2.4.48 Mod_Proxy - Server-Side Request Forgery

Cisco Adaptive Security Appliance (ASA)/Firepower Threat Defense (FTD) - Local File Inclusion

Oracle WebLogic Server (LFI)

Oracle E-Business Suite <=12.2 - Authentication Bypass

Microsoft Windows 'HTTP.sys' - Remote Code Execution

Cisco Adaptive Security Appliance Software/Cisco Firepower Threat Defense - Directory Traversal

Defender Security < 4.1.0 - Protection Bypass (Hidden Login Page)

mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as…