6.5

CVSS3.1

CVE-2024-50651 -

java_shop 1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter.

๐Ÿ“… Published: Nov. 15, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 27, 2024, 9:15 p.m.

5.9

CVSS3.1

CVE-2024-24452 -

An invalid memory access when handling the ProtocolIE_ID field ofย E-RAB Release Indication messages in Athonet vEPC MME v11.4.0ย allows attackers to cause a Denial of Service (DoS) to the cellularย network by repeatedly initiating connections and sending a craftedย payload.

๐Ÿ“… Published: Nov. 15, 2024, midnight ๐Ÿ”„ Last Modified: March 31, 2025, 9:15 p.m.

9.8

CVSS3.1

CVE-2024-50649 -

The user avatar upload function in python_book V1.0 has an arbitrary file upload vulnerability.

๐Ÿ“… Published: Nov. 15, 2024, midnight ๐Ÿ”„ Last Modified: June 17, 2025, 1:15 a.m.

6.1

CVSS3.1

CVE-2024-50983 -

FlightPath 7.5 contains a Cross Site Scripting (XSS) vulnerability, which allows authenticated remote attackers with administrative rights to inject arbitrary JavaScript in the web browser of a user by including a malicious payload into the Last Name section in the Create/Edit Faculty/Staff User orโ€ฆ

๐Ÿ“… Published: Nov. 15, 2024, midnight ๐Ÿ”„ Last Modified: July 7, 2025, 4:12 p.m.

7.5

CVSS3.1

CVE-2024-45969 -

NULL pointer dereference in the MMS Client in MZ Automation LibIEC1850 before commit 7afa40390b26ad1f4cf93deaa0052fe7e357ef33 allows a malicious server to Cause a Denial-of-Service via the MMS InitiationResponse message.

๐Ÿ“… Published: Nov. 15, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 18, 2024, 5:11 p.m.

6.5

CVSS3.1

CVE-2024-24446 -

An uninitialized pointer dereference in OpenAirInterface CN5G AMF up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a crafted InitialContextSetupResponse message sent to the AMF.

๐Ÿ“… Published: Nov. 15, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 19, 2024, 5:35 p.m.

9.8

CVSS3.1

CVE-2024-45970 -

Multiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit ac925fae8e281ac6defcd630e9dd756264e9c5bc allow a malicious server to cause a stack-based buffer overflow via the MMS FileDirResponse message.

๐Ÿ“… Published: Nov. 15, 2024, midnight ๐Ÿ”„ Last Modified: Oct. 1, 2025, 5:45 p.m.

7.3

CVSS3.1

CVE-2024-50986 -

An issue in Clementine v.1.3.1 allows a local attacker to execute arbitrary code via a crafted DLL file.

๐Ÿ“… Published: Nov. 15, 2024, midnight ๐Ÿ”„ Last Modified: July 7, 2025, 5:03 p.m.

6.1

CVSS3.1

CVE-2024-50800 -

Cross Site Scripting vulnerability in M2000 Smart4Web before v.5.020241004 allows a remote attacker to execute arbitrary code via the error parameter in URL

๐Ÿ“… Published: Nov. 15, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 18, 2024, 5:11 p.m.

7.8

CVSS3.1

CVE-2024-46465 -

By default, dedicated folders of CRYHOD for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of CRYHOD has to be modified to prevent this vulnerability.

๐Ÿ“… Published: Nov. 15, 2024, midnight ๐Ÿ”„ Last Modified: Oct. 1, 2025, 6:12 p.m.
Total resulsts: 343975
Page 7349 of 34,398
ยซ previous page ยป next page
Filters