5.7

CVSS3.1

CVE-2024-52520 - Nextcloud Server's link reference provider can be tricked into downloading bigger files than intend…

Nextcloud Server is a self hosted personal cloud system. Due to a pre-flighted HEAD request, the link reference provider could be tricked into downloading bigger websites than intended, to find open-graph data. It is recommended that the Nextcloud Server is upgraded to 28.0.10 or 29.0.7 and Nextclo…

📅 Published: Nov. 15, 2024, 4:41 p.m. 🔄 Last Modified: Sept. 5, 2025, midnight

4.9

CVSS3.1

CVE-2021-1470 - Cisco SD-WAN SQL Injection Vulnerability

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to improper input validation of SQL queries to an affected system. An attacker…

📅 Published: Nov. 15, 2024, 4:38 p.m. 🔄 Last Modified: June 24, 2025, 2:35 p.m.

2.6

CVSS3.1

CVE-2024-52521 - Nextcloud Server has a potential hash collision for background jobs could skip queuing them

Nextcloud Server is a self hosted personal cloud system. MD5 hashes were used to check background jobs for their uniqueness. This increased the chances of a background job with arguments falsely being identified as already existing and not be queued for execution. By changing the Hash to SHA256 the…

📅 Published: Nov. 15, 2024, 4:38 p.m. 🔄 Last Modified: Jan. 23, 2025, 2:52 p.m.

4.3

CVSS3.1

CVE-2021-1481 - Cisco SD-WAN vManage Cypher Query Language Injection Vulnerability

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct Cypher query language injection attacks on an affected system. This vulnerability is due to insufficient input validation by the web-based management…

📅 Published: Nov. 15, 2024, 4:37 p.m. 🔄 Last Modified: Aug. 4, 2025, 2:38 p.m.

6.4

CVSS3.1

CVE-2021-1482 - Cisco SD-WAN vManage Authorization Bypass Vulnerability

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization checking and gain access to sensitive information on an affected system. This vulnerability is due to insufficient authorization checks.…

📅 Published: Nov. 15, 2024, 4:36 p.m. 🔄 Last Modified: Aug. 4, 2025, 2:39 p.m.

4.6

CVSS3.1

CVE-2024-52523 - Nextcloud Server Custom defined credentials of external storages are sent back to the frontend

Nextcloud Server is a self hosted personal cloud system. After setting up a user or administrator defined external storage with fixed credentials, the API returns them and adds them into the frontend again, allowing to read them in plain text when an attacker already has access to an active session…

📅 Published: Nov. 15, 2024, 4:35 p.m. 🔄 Last Modified: Oct. 1, 2025, 6:30 p.m.

5

CVSS3.1

CVE-2021-1464 - Cisco SD-WAN vManage Authorization Bypass Vulnerability

A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization checking and gain restricted access to the configuration information of an affected system. This vulnerability exists because the affected software has insufficient input val…

📅 Published: Nov. 15, 2024, 4:32 p.m. 🔄 Last Modified: Aug. 4, 2025, 2:36 p.m.

5.3

CVSS4.0

CVE-2024-11247 - SourceCodester Online Eyewear Shop Inventory Page Master.php cross site scripting

A vulnerability has been found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /oews/classes/Master.php?f=save_product of the component Inventory Page. The manipulation of the argument brand leads to cro…

📅 Published: Nov. 15, 2024, 4:31 p.m. 🔄 Last Modified: Nov. 19, 2024, 9:55 p.m.

1.8

CVSS3.1

CVE-2024-52525 - Nextcloud Server User password is available in memory of the PHP process

Nextcloud Server is a self hosted personal cloud system. Under certain conditions the password of a user was stored unencrypted in the session data. The session data is encrypted before being saved in the session storage (Redis or disk), but it would allow a malicious process that gains access to t…

📅 Published: Nov. 15, 2024, 4:30 p.m. 🔄 Last Modified: Jan. 23, 2025, 2:33 p.m.

6.4

CVSS3.1

CVE-2021-1483 - Cisco SD-WAN vManage Software XML External Entity Vulnerability

A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. This vulnerability is due to improper handling of XML External Entity (XXE) entries when the affected…

📅 Published: Nov. 15, 2024, 4:27 p.m. 🔄 Last Modified: Aug. 4, 2025, 2:41 p.m.
Total resulsts: 344059
Page 7342 of 34,406
« previous page » next page
Filters