5.3

CVSS3.1

CVE-2024-52615 - Avahi: avahi wide-area dns uses constant source port

A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected.

📅 Published: Nov. 15, 2024, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS3.1

CVE-2024-50652 -

A file upload vulnerability in java_shop 1.0 allows attackers to upload arbitrary files by modifying the avatar function.

📅 Published: Nov. 15, 2024, midnight 🔄 Last Modified: Nov. 22, 2024, midnight

5.9

CVSS3.1

CVE-2024-24455 -

An invalid memory access when handling a UE Context Release message containing an invalid UE identifier in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.

📅 Published: Nov. 15, 2024, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-50651 -

java_shop 1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter.

📅 Published: Nov. 15, 2024, midnight 🔄 Last Modified: Nov. 27, 2024, 9:15 p.m.

6.1

CVSS3.1

CVE-2024-48068 -

A cross-site scripting (XSS) vulnerability in Shenzhen Landray Software Co.,LTD Landray EKP v16 and earlier allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

📅 Published: Nov. 15, 2024, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS3.1

CVE-2024-24452 -

An invalid memory access when handling the ProtocolIE_ID field of E-RAB Release Indication messages in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.

📅 Published: Nov. 15, 2024, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-50649 -

The user avatar upload function in python_book V1.0 has an arbitrary file upload vulnerability.

📅 Published: Nov. 15, 2024, midnight 🔄 Last Modified: June 17, 2025, 1:15 a.m.

5.3

CVSS3.1

CVE-2024-24450 -

Stack-based memcpy buffer overflow in the ngap_handle_pdu_session_resource_setup_response routine in OpenAirInterface CN5G AMF <= 2.0.0 allows a remote attacker with access to the N2 interface to carry out denial of service against the AMF and potentially execute code by sending a PDU Session Resou…

📅 Published: Nov. 15, 2024, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-50983 -

FlightPath 7.5 contains a Cross Site Scripting (XSS) vulnerability, which allows authenticated remote attackers with administrative rights to inject arbitrary JavaScript in the web browser of a user by including a malicious payload into the Last Name section in the Create/Edit Faculty/Staff User or…

📅 Published: Nov. 15, 2024, midnight 🔄 Last Modified: July 7, 2025, 4:12 p.m.

7.8

CVSS3.1

CVE-2024-46467 -

By default, dedicated folders of ZONEPOINT for Windows up to 2024.1 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of ZONEPOINT has to be modified to prevent this vulnerability.

📅 Published: Nov. 15, 2024, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 344690
Page 7420 of 34,469
« previous page » next page
Filters