6.8

CVSS3.1

CVE-2024-47616 - Pomerium's service account access token may grant unintended access to databroker API

Pomerium is an identity and context-aware access proxy. The Pomerium databroker service is responsible for managing all persistent Pomerium application state. Requests to the databroker service API are authorized by the presence of a JSON Web Token (JWT) signed by a key known by all Pomerium servic…

πŸ“… Published: Oct. 2, 2024, 9:10 p.m. πŸ”„ Last Modified: July 12, 2025, 11:06 p.m.

8.8

CVSS3.1

CVE-2024-28888 -

A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a checkbox field object. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution. An attacker …

πŸ“… Published: Oct. 2, 2024, 8:51 p.m. πŸ”„ Last Modified: Sept. 23, 2025, 3:15 p.m.

4.8

CVSS4.0

CVE-2024-47529 - OpenC3 COSMOS uses clear text storage of password/token (`GHSL-2024-129`)

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. OpenC3 COSMOS stores the password of a user unencrypted in the LocalStorage of a web browser. This makes the user password susceptible to exfiltration via Cross-site scripting (se…

πŸ“… Published: Oct. 2, 2024, 7:17 p.m. πŸ”„ Last Modified: Nov. 13, 2024, 5:15 p.m.

5.3

CVSS4.0

CVE-2024-46977 - OpenC3 COSMOS allows a path traversal via screen controller (`GHSL-2024-127`)

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. A path traversal vulnerability inside of LocalMode's open_local_file method allows an authenticated user with adequate permissions to download any .txt via the ScreensController#s…

πŸ“… Published: Oct. 2, 2024, 7:17 p.m. πŸ”„ Last Modified: Oct. 31, 2024, 2:15 p.m.

5.1

CVSS4.0

CVE-2024-43795 - OpenC3 COSMOS vulnerable to cross-site scripting in Login functionality (`GHSL-2024-128`)

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. The login functionality contains a reflected cross-site scripting (XSS) vulnerability. This vulnerability is fixed in 5.19.0. Note: This CVE only affects Open Source Edition, and …

πŸ“… Published: Oct. 2, 2024, 7:13 p.m. πŸ”„ Last Modified: Oct. 31, 2024, 2:15 p.m.

8

CVSS3.1

CVE-2024-8733 - HP One Agent Software – Potential Privilege Escalation

A potential security vulnerability has been identified in the HP One Agent for certain HP PC products, which might allow for escalation of privilege. HP is releasing software updates to mitigate this potential vulnerability.

πŸ“… Published: Oct. 2, 2024, 7:12 p.m. πŸ”„ Last Modified: Oct. 4, 2024, 1:50 p.m.

9.8

CVSS3.1

CVE-2024-9441 - Linear eMerge e3-Series Forgot Password Command Injection

The Linear eMerge e3-Series through version 1.00-07 is vulnerable to an OS command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary OS commands via the login_id parameter when invoking the forgot_password functionality over HTTP.

πŸ“… Published: Oct. 2, 2024, 6:50 p.m. πŸ”„ Last Modified: Oct. 4, 2024, 1:50 p.m.

5.4

CVSS3.1

CVE-2024-9440 - Slim Select 2.0 createOption "text" XSS

Slim Select 2.0 versions through 2.9.0 are affected by a potential cross-site scripting vulnerability. In select.ts:createOption(), the text variable from the user-provided Options object is assigned to an innerHTML without sanitation. Software that depends on this library to dynamically generate l…

πŸ“… Published: Oct. 2, 2024, 6:40 p.m. πŸ”„ Last Modified: Nov. 29, 2025, 2:04 a.m.

5.8

CVSS3.1

CVE-2024-20509 -

A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to hijack an AnyConnect VPN session or cause a denial of service (DoS) condition for individual users of the AnyConnect VPN serv…

πŸ“… Published: Oct. 2, 2024, 6:24 p.m. πŸ”„ Last Modified: June 4, 2025, 9:15 p.m.

5.8

CVSS3.1

CVE-2024-20513 -

A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition for targeted users of the AnyConnect service on an affected device. This vulnerability is due to ins…

πŸ“… Published: Oct. 2, 2024, 6:23 p.m. πŸ”„ Last Modified: June 4, 2025, 9:15 p.m.
Total resulsts: 342251
Page 7721 of 34,226
Β« previous page Β» next page
Filters