6.5

CVSS3.1

CVE-2024-34146 - jenkins-plugin/git-server: missing permission check in Git server Plugin

Jenkins Git server Plugin 114.v068a_c7cc2574 and earlier does not perform a permission check for read access to a Git repository over SSH, allowing attackers with a previously configured SSH public key but lacking Overall/Read permission to access these repositories.

πŸ“… Published: May 2, 2024, midnight πŸ”„ Last Modified: Oct. 10, 2025, 3:34 p.m.

8.8

CVSS3.1

CVE-2024-34145 - jenkins-plugin/script-security: sandbox bypass via sandbox-defined classes

A sandbox bypass vulnerability involving sandbox-defined classes that shadow specific non-sandbox-defined classes in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protec…

πŸ“… Published: May 2, 2024, midnight πŸ”„ Last Modified: Oct. 10, 2025, 3:34 p.m.

6.1

CVSS3.1

CVE-2024-33305 -

SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "Middle Name" parameter in Create User.

πŸ“… Published: May 2, 2024, midnight πŸ”„ Last Modified: April 22, 2025, 4:14 p.m.

6.2

CVSS3.1

CVE-2024-31966 -

A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit through 5.1.1 SP8 allows an authenticated attacker with administrative privilege to conduct an argument injection attack due to insufficient parameter …

πŸ“… Published: May 2, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-31963 -

A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit through 5.1.1 SP8 allows an authenticated attacker to conduct a buffer overflow attack due to insufficient bounds checking and input sanitization. A su…

πŸ“… Published: May 2, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.2

CVSS3.1

CVE-2024-4418 - Libvirt: stack use-after-free in virnetclientioeventloop()

A race condition leading to a stack use-after-free flaw was found in libvirt. Due to a bad assumption in the virNetClientIOEventLoop() method, the `data` pointer to a stack-allocated virNetClientIOEventData structure ended up being used in the virNetClientIOEventFD callback while the data pointer's…

πŸ“… Published: May 2, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.1

CVSS3.1

CVE-2024-4029 - Wildfly: no timeout for eap management interface may lead to denial of service (dos)

A vulnerability was found in Wildfly’s management interface. Due to the lack of limitation of sockets for the management interface, it may be possible to cause a denial of service hitting the nofile limit as there is no possibility to configure or set a maximum number of connections.

πŸ“… Published: May 2, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.2

CVSS3.1

CVE-2024-33303 -

SourceCodester Product Show Room 1.0 is vulnerable to Cross Site Scripting (XSS) via "First Name" under Add Users.

πŸ“… Published: May 2, 2024, midnight πŸ”„ Last Modified: April 22, 2025, 4:16 p.m.

7.5

CVSS3.1

CVE-2024-33530 -

In Jitsi Meet before 9391, a logic flaw in password-protected Jitsi meetings (that make use of a lobby) leads to the disclosure of the meeting password when a user is invited to a call after waiting in the lobby.

πŸ“… Published: May 2, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.4

CVSS3.1

CVE-2024-33396 -

An issue in karmada-io karmada v1.9.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.

πŸ“… Published: May 2, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 10093 of 34,919
Β« previous page Β» next page
Filters