5.3

CVSS4.0

CVE-2024-10546 - open-scratch Teaching 在线教学平台 URL getDictItemsByTable sql injection

A vulnerability classified as critical was found in open-scratch Teaching 在线教学平台 up to 2.7. This vulnerability affects unknown code of the file /api/sys/ng-alain/getDictItemsByTable/ of the component URL Handler. The manipulation leads to sql injection. The attack can be initiated remotely. The exp…

📅 Published: Oct. 30, 2024, 7:31 p.m. 🔄 Last Modified: Nov. 21, 2024, 8:48 a.m.

9.3

CVSS4.0

CVE-2024-10456 - Delta Electronics InfraSuite Device Master Deserialization of Untrusted Data

Delta Electronics InfraSuite Device Master versions prior to 1.0.12 are affected by a deserialization vulnerability that targets the Device-Gateway, which could allow deserialization of arbitrary .NET objects prior to authentication.

📅 Published: Oct. 30, 2024, 6:04 p.m. 🔄 Last Modified: Nov. 1, 2024, 12:57 p.m.

7.8

CVSS3.1

CVE-2024-9419 - Certain HP Print Products–Potential Remote Code Execution and/or Elevation of Privilege with the HP…

Client / Server PCs with the HP Smart Universal Printing Driver installed are potentially vulnerable to Remote Code Execution and/or Elevation of Privilege. A client using the HP Smart Universal Printing Driver that sends a print job comprised of a malicious XPS file could potentially lead to Remot…

📅 Published: Oct. 30, 2024, 5:25 p.m. 🔄 Last Modified: Jan. 26, 2026, 6 p.m.

6.4

CVSS3.1

CVE-2024-9110 - Cross-Site Scripting In Privileged Identity

A medium severity vulnerability has been identified within Privileged Identity which can allow an attacker to perform reflected cross-site scripting attacks.

📅 Published: Oct. 30, 2024, 4:57 p.m. 🔄 Last Modified: Feb. 11, 2025, 8:43 p.m.

4.6

CVSS3.1

CVE-2024-50344 - I, Librarian has a Stored XSS vulnerability in Supplemental Files

I, Librarian is an open-source version of a PDF managing SaaS. Supplemental Files are allowed to be viewed in the browser, only if they have a white-listed MIME type. Unfortunately, this logic is broken, thus allowing unsafe files containing Javascript to be executed with the application context. A…

📅 Published: Oct. 30, 2024, 3:51 p.m. 🔄 Last Modified: Nov. 1, 2024, 12:57 p.m.

9.8

CVSS3.1

CVE-2024-50419 - WordPress Greenshift plugin <=9.7 - Broken Access Control vulnerability

Incorrect Authorization vulnerability in wpsoul Greenshift greenshift-animation-and-page-builder-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Greenshift: from n/a through <= 9.7.

📅 Published: Oct. 30, 2024, 3:01 p.m. 🔄 Last Modified: April 1, 2026, 4:19 p.m.

5.3

CVSS3.1

CVE-2024-50353 - ICG.AspNetCore.Utilities.CloudStorage's Secure Token Durations Different Than Expected

ICG.AspNetCore.Utilities.CloudStorage is a collection of cloud storage utilities to assist with the management of files for cloud upload. Users of this library that set a duration for a SAS Uri with a value other than 1 hour may have generated a URL with a duration that is longer, or shorter than d…

📅 Published: Oct. 30, 2024, 1:57 p.m. 🔄 Last Modified: Nov. 13, 2024, 3:15 p.m.

8.1

CVSS3.1

CVE-2024-31151 -

A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain unauthorized access during the first 30 seconds post-boot. Other vulnerabilities can force a reboot, circumventing the initial time restriction for exploitation.The password string can be f…

📅 Published: Oct. 30, 2024, 1:35 p.m. 🔄 Last Modified: Nov. 3, 2025, 10:16 p.m.

8.1

CVSS3.1

CVE-2024-28875 -

A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain unauthorized access during the first 30 seconds post-boot. Other vulnerabilities can force a reboot, circumventing the initial time restriction for exploitation.The backdoor string can be f…

📅 Published: Oct. 30, 2024, 1:35 p.m. 🔄 Last Modified: Nov. 3, 2025, 10:16 p.m.

8.8

CVSS3.1

CVE-2024-24777 -

A cross-site request forgery (CSRF) vulnerability exists in the Web Application functionality of the LevelOne WBR-6012 R0.40e6. A specially crafted HTTP request can lead to unauthorized access. An attacker can stage a malicious web page to trigger this vulnerability.

📅 Published: Oct. 30, 2024, 1:35 p.m. 🔄 Last Modified: Nov. 21, 2024, 8:59 a.m.
Total resulsts: 343996
Page 7562 of 34,400
« previous page » next page
Filters