9.1

CVSS3.1

CVE-2024-51164 -

Multiple parameters have SQL injection vulnerability in JEPaaS 7.2.8 via /je/login/btnLog/insertBtnLog, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.

πŸ“… Published: Nov. 15, 2024, midnight πŸ”„ Last Modified: June 24, 2025, 2:37 p.m.

7.5

CVSS3.1

CVE-2024-50647 -

The python_food ordering system V1.0 has an unauthorized vulnerability that leads to the leakage of sensitive user information. Attackers can access it through https://ip:port/api/myapp/index/user/info?id=1 And modify the ID value to obtain sensitive user information beyond authorization.

πŸ“… Published: Nov. 15, 2024, midnight πŸ”„ Last Modified: Dec. 3, 2024, 5:15 p.m.

7.8

CVSS3.1

CVE-2024-46467 -

By default, dedicated folders of ZONEPOINT for Windows up to 2024.1 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of ZONEPOINT has to be modified to prevent this vulnerability.

πŸ“… Published: Nov. 15, 2024, midnight πŸ”„ Last Modified: Nov. 25, 2024, 8:15 p.m.

9.8

CVSS3.1

CVE-2024-50648 -

yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP files.

πŸ“… Published: Nov. 15, 2024, midnight πŸ”„ Last Modified: June 17, 2025, 1:19 a.m.

6.1

CVSS3.1

CVE-2024-50655 -

emlog pro <=2.3.18 is vulnerable to Cross Site Scripting (XSS), which allows attackers to write malicious JavaScript code in published articles.

πŸ“… Published: Nov. 15, 2024, midnight πŸ”„ Last Modified: Nov. 21, 2024, 9:44 a.m.

7.5

CVSS3.1

CVE-2024-24431 -

A reachable assertion in the ogs_nas_emm_decode function of Open5GS v2.7.0 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet with a zero-length EMM message length.

πŸ“… Published: Nov. 15, 2024, midnight πŸ”„ Last Modified: April 22, 2025, 5:26 p.m.

2.4

CVSS3.1

CVE-2024-46383 -

Hathway Skyworth Router CM5100-511 v4.1.1.24 was discovered to store sensitive information about USB and Wifi connected devices in plaintext.

πŸ“… Published: Nov. 15, 2024, midnight πŸ”„ Last Modified: Nov. 18, 2024, 5:11 p.m.

9.8

CVSS3.1

CVE-2024-45971 -

Multiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit 1f52be9ddeae00e69cd43e4cac3cb4f0c880c4f0 allow a malicious server to cause a stack-based buffer overflow via the MMS IdentifyResponse message.

πŸ“… Published: Nov. 15, 2024, midnight πŸ”„ Last Modified: Oct. 1, 2025, 5:45 p.m.

5.3

CVSS3.1

CVE-2024-52616 - Avahi: avahi wide-area dns predictable transaction ids

A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs.

πŸ“… Published: Nov. 15, 2024, midnight πŸ”„ Last Modified: March 24, 2026, 5:16 p.m.

7.8

CVSS3.1

CVE-2024-46466 -

By default, dedicated folders of ZONECENTRAL for Windows up to 2024.3 or up to Q.2021.2 (ANSSI qualification submission) can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of ZONECENTRAL has to be modified to prevent this vulne…

πŸ“… Published: Nov. 15, 2024, midnight πŸ”„ Last Modified: July 12, 2025, 10:31 p.m.
Total resulsts: 343980
Page 7348 of 34,398
Β« previous page Β» next page
Filters