7.2

CVSS3.1

CVE-2024-47910 -

An issue was discovered in SonarSource SonarQube before 9.9.5 LTA and 10.x before 10.5. A SonarQube user with the Administrator role can modify an existing configuration of a GitHub integration to exfiltrate a pre-signed JWT.

๐Ÿ“… Published: Oct. 4, 2024, midnight ๐Ÿ”„ Last Modified: Oct. 7, 2024, 7:37 p.m.

6.1

CVSS3.1

CVE-2024-47854 -

An XSS vulnerability was discovered in Veritas Data Insight before 7.1. It allows a remote attacker to inject an arbitrary web script into an HTTP request that could reflect back to an authenticated user without sanitization if executed by that user.

๐Ÿ“… Published: Oct. 4, 2024, midnight ๐Ÿ”„ Last Modified: Oct. 17, 2025, 3:15 p.m.

5.3

CVSS3.1

CVE-2024-47855 - json-lib: Mishandling of an unbalanced comment string in json-lib

util/JSONTokener.java in JSON-lib before 3.1.0 mishandles an unbalanced comment string.

๐Ÿ“… Published: Oct. 4, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 7, 2024, 8:35 p.m.

5.3

CVSS3.1

CVE-2024-47913 -

An issue was discovered in the AbuseFilter extension for MediaWiki before 1.39.9, 1.40.x and 1.41.x before 1.41.3, and 1.42.x before 1.42.2. An API caller can match a filter condition against AbuseFilter logs even if the caller is not authorized to view the log details for the filter.

๐Ÿ“… Published: Oct. 4, 2024, midnight ๐Ÿ”„ Last Modified: June 17, 2025, 3:54 p.m.

5.4

CVSS3.1

CVE-2024-41516 -

A Reflected cross-site scripting (XSS) vulnerability in "ccHandler.aspx" CADClick <= 1.11.0 allows remote attackers to inject arbitrary web script or HTML via the "bomid" parameter.

๐Ÿ“… Published: Oct. 4, 2024, midnight ๐Ÿ”„ Last Modified: June 2, 2025, 5:40 p.m.

7.5

CVSS3.1

CVE-2024-47850 - cups-browsed: cups-filters: cups-browsed vulnerable to DDoS amplification attack

CUPS cups-browsed before 2.5b1 will send an HTTP POST request to an arbitrary destination and port in response to a single IPP UDP packet requesting a printer to be added, a different vulnerability than CVE-2024-47176. (The request is meant to probe the new printer but can be used to create DDoS amโ€ฆ

๐Ÿ“… Published: Oct. 4, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:40 a.m.

9.8

CVSS3.1

CVE-2023-26770 -

TaskCafe 0.3.2 lacks validation in the Cookie value. Any unauthenticated attacker who knows a registered UserID can change the password of that user.

๐Ÿ“… Published: Oct. 4, 2024, midnight ๐Ÿ”„ Last Modified: May 27, 2025, 7:18 p.m.

8.8

CVSS3.1

CVE-2024-41512 -

A SQL Injection vulnerability in "ccHandler.aspx" in all versions of CADClick v.1.11.0 and before allows remote attackers to execute arbitrary SQL commands via the "bomid" parameter.

๐Ÿ“… Published: Oct. 4, 2024, midnight ๐Ÿ”„ Last Modified: June 2, 2025, 5:40 p.m.

7.1

CVSS3.1

CVE-2024-47191 - oath-toolkit: Local root exploit in a PAM module

pam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because, in the context of PAM code running as root, it mishandles usersfile access, such as by calling fchown in the presence of a symlink.

๐Ÿ“… Published: Oct. 4, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:39 a.m.

8

CVSS3.1

CVE-2024-46486 -

TP-LINK TL-WDR5620 v2.3 was discovered to contain a remote code execution (RCE) vulnerability via the httpProcDataSrv function.

๐Ÿ“… Published: Oct. 4, 2024, midnight ๐Ÿ”„ Last Modified: Aug. 15, 2025, 8:39 p.m.
Total resulsts: 342292
Page 7717 of 34,230
ยซ previous page ยป next page
Filters