CVE-2024-25293

CRITICAL Year: 2024
CVSS v3 Score
9.3
Critical

Vulnerability Description

mjml-app versions 3.0.4 and 3.1.0-beta were discovered to contain a remote code execution (RCE) via the href attribute.

CVSS:9.4(Critical)

remote code execution in paddlepaddle/paddle 2.6.0

CWE-942024
CVSS:9.4(Critical)

OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. `CompiledRule::validateExpr...

CWE-942024
CVSS:9.1(Critical)

Adobe Campaign versions 16.4 Build 8724 and earlier have a code injection vulnerability.

CWE-942017
CVSS:9.1(Critical)

The OS Command Plugin in the transaction GPA_ADMIN and the OSCommand Console of SAP Diagnostic Agent (LM-Service), version 7.2, allow an attacker to inject code that can be executed by the application...

CWE-942019
CVSS:9.1(Critical)

Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to patch 71 contain a server-side template injection vulnerability in the REST API. A ...

CWE-942019