7.5

CVSS3.1

CVE-2024-50650 -

python_book V1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter.

๐Ÿ“… Published: Nov. 15, 2024, midnight ๐Ÿ”„ Last Modified: June 17, 2025, 1:10 a.m.

6.1

CVSS3.1

CVE-2024-48068 -

A cross-site scripting (XSS) vulnerability in Shenzhen Landray Software Co.,LTD Landray EKP v16 and earlier allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

๐Ÿ“… Published: Nov. 15, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 21, 2024, 7:15 p.m.

6.5

CVSS3.1

CVE-2024-24425 -

Magma v1.8.0 and OAI EPC Federation v1.20 were discovered to contain an out-of-bounds read in the amf_as_establish_req function at /tasks/amf/amf_as.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.

๐Ÿ“… Published: Nov. 15, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 19, 2024, 5:35 p.m.

7.8

CVSS3.1

CVE-2024-46463 -

By default, dedicated folders of ORIZON for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of ORIZON has to be modified to prevent this vulnerability.

๐Ÿ“… Published: Nov. 15, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 25, 2024, 8:15 p.m.

5.3

CVSS3.1

CVE-2024-24450 -

Stack-based memcpy buffer overflow in the ngap_handle_pdu_session_resource_setup_response routine in OpenAirInterface CN5G AMF <= 2.0.0 allows a remote attacker with access to the N2 interface to carry out denial of service against the AMF and potentially execute code by sending a PDU Session Resouโ€ฆ

๐Ÿ“… Published: Nov. 15, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 18, 2024, 5:11 p.m.

4.6

CVSS3.1

CVE-2024-23169 -

The web interface in RSA NetWitness 11.7.2.0 allows Cross-Site Scripting (XSS) via the Where textbox on the Reports screen during new rule creation.

๐Ÿ“… Published: Nov. 15, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 18, 2024, 5:11 p.m.

9.8

CVSS3.1

CVE-2024-50724 -

KASO v9.0 was discovered to contain a SQL injection vulnerability via the person_id parameter at /cardcase/editcard.jsp.

๐Ÿ“… Published: Nov. 15, 2024, midnight ๐Ÿ”„ Last Modified: Dec. 3, 2024, 5:15 p.m.

5.9

CVSS3.1

CVE-2024-24459 -

An invalid memory access when handling the ProtocolIE_ID field ofย S1Setup Request messages in Athonet vEPC MME v11.4.0 allowsย attackers to cause a Denial of Service (DoS) to the cellular network byย repeatedly initiating connections and sending a crafted payload.

๐Ÿ“… Published: Nov. 15, 2024, midnight ๐Ÿ”„ Last Modified: Aug. 26, 2025, 10:15 p.m.

6.5

CVSS3.1

CVE-2024-24449 -

An uninitialized pointer dereference in the NasPdu::NasPdu component of OpenAirInterface CN5G AMF up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a crafted InitialUEMessage message sent to the AMF.

๐Ÿ“… Published: Nov. 15, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 26, 2024, 7:15 p.m.

8.8

CVSS3.1

CVE-2024-44625 -

Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go.

๐Ÿ“… Published: Nov. 15, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:36 a.m.
Total resulsts: 343975
Page 7350 of 34,398
ยซ previous page ยป next page
Filters