NVD disclosure day

Published threat advisories for December 10, 2024

CVE advisoryCRITICAL

CVE-2024-53480

Phpgurukul Beauty Parlour Management System SQL Injection in Login

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability in the Beauty Parlour Management System could allow unauthenticated attackers to manipulate database queries via the login page, potentially exposing or modifying sensitive information. It is uncertain if this specific system is in use, making it important to identify and assess a

CVE advisoryKnown Exploit

CVE-2024-55550

Mitel MiCollab Authenticated File Read Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Mitel MiCollab software has a vulnerability that allows an authenticated administrator to read non-sensitive system files due to insufficient input sanitization. This could enable attackers with existing administrative access to access restricted resources. This issue is listed in the Known Exploited Vulnerabilities ca

• CISA KEV

CVE advisoryCRITICAL

CVE-2024-46442

BYD Dilink Headunit Authentication Bypass Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An authentication bypass vulnerability exists in the BYD Dilink Headunit System that permits attackers to gain unauthorized access through brute-force attacks. This could potentially lead to a complete system compromise if the affected technology is reachable. Readers should care to confirm if this automotive system is