7.5

CVSS3.1

CVE-2024-56375 -

An integer underflow was discovered in Fort 1.6.3 and 1.6.4 before 1.6.5. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a Manifest RPKI object containing an empty fileList. Fort dereferences (and, shortly afterwards, writes to) this array duri…

πŸ“… Published: Dec. 22, 2024, midnight πŸ”„ Last Modified: April 22, 2025, 3:54 p.m.

5.4

CVSS3.1

CVE-2024-56313 -

A stored cross-site scripting (XSS) vulnerability in the Calendar feature of REDCap through 14.9.6 allows authenticated users to inject malicious scripts into the Notes field of a calendar event. When the event is viewed, the crafted payload is executed, potentially enabling the execution of arbitr…

πŸ“… Published: Dec. 22, 2024, midnight πŸ”„ Last Modified: April 22, 2025, 3:43 p.m.

4.3

CVSS3.1

CVE-2024-56378 - Poppler: out-of-bounds read

libpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine function in JBIG2Stream.cc.

πŸ“… Published: Dec. 22, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:16 p.m.

5.4

CVSS3.1

CVE-2024-56314 -

A stored cross-site scripting (XSS) vulnerability in the Project name of REDCap through 14.9.6 allows authenticated users to inject malicious scripts into the name field of a Project. When a user clicks on the project name to access it, the crafted payload is executed, potentially enabling the exec…

πŸ“… Published: Dec. 22, 2024, midnight πŸ”„ Last Modified: April 22, 2025, 3:43 p.m.

5.4

CVSS3.1

CVE-2024-56312 -

A stored cross-site scripting (XSS) vulnerability in the Project Dashboard name of REDCap through 14.9.6 allows authenticated users to inject malicious scripts into the name field of a Project Dashboard. When a user clicks on the project Dashboard name, the crafted payload is executed, potentially …

πŸ“… Published: Dec. 22, 2024, midnight πŸ”„ Last Modified: April 22, 2025, 3:43 p.m.

8.8

CVSS3.1

CVE-2024-56311 -

REDCap through 14.9.6 has a security flaw in the Notes section of calendar events, exposing users to a Cross-Site Request Forgery (CSRF) attack. An attacker can exploit this by luring users into accessing a calendar event's notes, which triggers a logout request and terminates their session. This v…

πŸ“… Published: Dec. 22, 2024, midnight πŸ”„ Last Modified: April 22, 2025, 3:43 p.m.

8.8

CVSS3.1

CVE-2024-56310 -

REDCap through 14.9.6 has a security flaw in the Project Dashboards name, exposing users to a Cross-Site Request Forgery (CSRF) attack. An attacker can exploit this by luring users into clicking on a Project Dashboards name that contains the malicious payload, which triggers a logout request and te…

πŸ“… Published: Dec. 22, 2024, midnight πŸ”„ Last Modified: April 22, 2025, 3:37 p.m.

6.9

CVSS4.0

CVE-2024-12884 - Codezips E-Commerce Website login.php sql injection

A vulnerability was found in Codezips E-Commerce Website 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclose…

πŸ“… Published: Dec. 21, 2024, 2 p.m. πŸ”„ Last Modified: Jan. 10, 2025, 9:22 p.m.

5.4

CVSS3.1

CVE-2024-51463 - IBM i server-side request forgery

IBM i 7.3, 7.4, and 7.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

πŸ“… Published: Dec. 21, 2024, 1:46 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 11:17 p.m.

4.3

CVSS3.1

CVE-2024-51464 - IBM i authentication bypass

IBM i 7.3, 7.4, and 7.5 is vulnerable to bypassing Navigator for i interface restrictions. By sending a specially crafted request, an authenticated attacker could exploit this vulnerability to remotely perform operations that the user is not allowed to perform when using Navigator for i.

πŸ“… Published: Dec. 21, 2024, 1:44 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 11:17 p.m.
Total resulsts: 344059
Page 6882 of 34,406
Β« previous page Β» next page
Filters