NVD disclosure day

Published threat advisories for November 26, 2024

CVE advisoryCRITICAL

CVE-2024-50942

qiwen-file SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in the qiwen-file component, allowing network-accessible exploitation. This could lead to unauthorized access, modification, or deletion of database content. Confirmation of the affected technology's presence and reachability within your environment is crucial to assess potential bu

CVE advisoryKnown Exploit

CVE-2024-49035

Microsoft Partner Center Privilege Escalation Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An improper access control vulnerability affects Microsoft Partner Center, allowing an unauthenticated attacker to gain elevated privileges over a network. This could lead to unauthorized access to sensitive data and system modifications, posing a significant business risk.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2024-11680

ProjectSend Improper Authentication Allows Configuration Changes

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An improper authentication vulnerability in ProjectSend allows unauthenticated attackers to modify application configurations. This could lead to unauthorized account creation, malicious file uploads, and JavaScript injection, impacting system integrity and data security.

• CISA KEV