7.5

CVSS3.1

CVE-2024-48768 -

An issue in almaodo GmbH appinventor.ai_google.almando_control 2.3.1 allows a remote attacker to obtain sensitive information via the firmware update process

πŸ“… Published: Oct. 11, 2024, midnight πŸ”„ Last Modified: Oct. 15, 2024, 9:35 p.m.

4.7

CVSS3.1

CVE-2024-44731 -

Mirotalk before commit 9de226 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary code via sending crafted payloads in messages to other users over RTC connections.

πŸ“… Published: Oct. 11, 2024, midnight πŸ”„ Last Modified: March 19, 2026, 5:16 p.m.

7.2

CVSS3.1

CVE-2024-45754 -

An issue was discovered in the centreon-bi-server component in Centreon BI Server 24.04.x before 24.04.3, 23.10.x before 23.10.8, 23.04.x before 23.04.11, and 22.10.x before 22.10.11. SQL injection can occur in the listing of configured reporting jobs. Exploitation is only accessible to authenticat…

πŸ“… Published: Oct. 11, 2024, midnight πŸ”„ Last Modified: Oct. 15, 2024, 4:35 p.m.

7.5

CVSS3.1

CVE-2024-48938 -

Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows DoS/ReDos via email. Parsing the content of emails where HTML code is copied from Microsoft Word could lead to high CPU usage and block the parsing process.

πŸ“… Published: Oct. 11, 2024, midnight πŸ”„ Last Modified: March 14, 2025, 2:15 p.m.

9.8

CVSS3.1

CVE-2024-46532 -

SQL Injection vulnerability in OpenHIS v.1.0 allows an attacker to execute arbitrary code via the refund function in the PayController.class.php component.

πŸ“… Published: Oct. 11, 2024, midnight πŸ”„ Last Modified: Oct. 16, 2024, 6:35 p.m.

6.1

CVSS3.1

CVE-2024-48937 -

Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows XSS. JavaScript code in the short description of the SLA field in Activity Dialogues is executed.

πŸ“… Published: Oct. 11, 2024, midnight πŸ”„ Last Modified: March 13, 2025, 2:15 p.m.

7.5

CVSS3.1

CVE-2024-48788 -

An issue in YESCAM (com.yescom.YesCam.zwave) 1.0.2 allows a remote attacker to obtain sensitive information via the firmware update process.

πŸ“… Published: Oct. 11, 2024, midnight πŸ”„ Last Modified: Oct. 15, 2024, 7:35 p.m.

9.8

CVSS3.1

CVE-2024-42640 -

angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Exploiting this vulnerability allows an attacker to upload arbitrary content to the server, which can subsequently be accessed through demo/uploads. This leads to the execution of prev…

πŸ“… Published: Oct. 11, 2024, midnight πŸ”„ Last Modified: Oct. 15, 2024, 5:35 p.m.

7.5

CVSS3.1

CVE-2024-48775 -

An issue in Plug n Play Camera com.ezset.delaney 1.2.0 allows a remote attacker to obtain sensitive information via the firmware update process.

πŸ“… Published: Oct. 11, 2024, midnight πŸ”„ Last Modified: Oct. 15, 2024, 8:35 p.m.

9.1

CVSS3.1

CVE-2024-48772 -

An issue in C-CHIP (com.cchip.cchipamaota) v.1.2.8 allows a remote attacker to obtain sensitive information via the firmware update process.

πŸ“… Published: Oct. 11, 2024, midnight πŸ”„ Last Modified: Oct. 15, 2024, 7:35 p.m.
Total resulsts: 343048
Page 7706 of 34,305
Β« previous page Β» next page
Filters