8.7

CVSS4.0

CVE-2024-47824 - Malicious homeservers can steal message keys when the matrix-react-sdk user invites another user toโ€ฆ

matrix-react-sdk is react-based software development kit for inserting a Matrix chat/VOIP client into a web page. Starting in version 3.18.0 and before 3.102.0, matrix-react-sdk allows a malicious homeserver to potentially steal message keys for a room when a user invites another user to that room,โ€ฆ

๐Ÿ“… Published: Oct. 15, 2024, 3:40 p.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 5:15 p.m.

3.7

CVSS3.1

CVE-2024-9506 - Regular Expression Denial of Service (ReDoS)

Improper regular expression in Vue's parseHTML function leads to a potential regular expression denial of service vulnerability.

๐Ÿ“… Published: Oct. 15, 2024, 3:40 p.m. ๐Ÿ”„ Last Modified: Oct. 16, 2024, 4:38 p.m.

7

CVSS4.0

CVE-2024-47779 - Element Web vulnerable to potential exposure of access token via authenticated media

Element is a Matrix web client built using the Matrix React SDK. Element Web versions 1.11.70 through 1.11.80 contain a vulnerability which can, under specially crafted conditions, lead to the access token becoming exposed to third parties. At least one vector has been identified internally, involvโ€ฆ

๐Ÿ“… Published: Oct. 15, 2024, 3:28 p.m. ๐Ÿ”„ Last Modified: Nov. 12, 2024, 5:15 p.m.

7

CVSS4.0

CVE-2024-47771 - Element Desktop vulnerable to potential exposure of access token via authenticated media

Element Desktop is a Matrix client for desktop platforms. Element Desktop versions 1.11.70 through 1.11.80 contain a vulnerability which can, under specially crafted conditions, lead to the access token becoming exposed to third parties. At least one vector has been identified internally, involvingโ€ฆ

๐Ÿ“… Published: Oct. 15, 2024, 3:02 p.m. ๐Ÿ”„ Last Modified: Oct. 16, 2024, 4:38 p.m.

6.5

CVSS3.1

CVE-2024-9676 - Podman: buildah: cri-o: symlink traversal vulnerability in the containers/storage library can causeโ€ฆ

A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image using an automatically assigned user namespace (`--โ€ฆ

๐Ÿ“… Published: Oct. 15, 2024, 3 p.m. ๐Ÿ”„ Last Modified: March 26, 2026, 12:42 p.m.

8.7

CVSS4.0

CVE-2024-47080 - matrix-js-sdk keys sent via `sendSharedHistoryKeys` vulnerable to interception by malicious homeserโ€ฆ

matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript. In matrix-js-sdk versions versions 9.11.0 through 34.7.0, the method `MatrixClient.sendSharedHistoryKeys` is vulnerable to interception by malicious homeservers. The method was introduced by MSC3061) and is commonly used โ€ฆ

๐Ÿ“… Published: Oct. 15, 2024, 2:53 p.m. ๐Ÿ”„ Last Modified: Oct. 16, 2024, 4:38 p.m.

0.0

CVE-2024-9998 -

The vulnerability has no impact, so it has been deprecated.

๐Ÿ“… Published: Oct. 15, 2024, 2:01 p.m. ๐Ÿ”„ Last Modified: Nov. 12, 2024, 11:15 a.m.

6.9

CVSS4.0

CVE-2024-9986 - code-projects Blood Bank Management System member_register.php sql injection

A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file member_register.php. The manipulation of the argument fullname/username/password/email leads to sql injection. The attack may be initiatโ€ฆ

๐Ÿ“… Published: Oct. 15, 2024, 1 p.m. ๐Ÿ”„ Last Modified: Oct. 23, 2025, 8:06 p.m.

5.1

CVSS4.0

CVE-2024-9977 - MitraStar GPT-2541GNAC Firewall Settings Page settings-firewall.cgi os command injection

A vulnerability, which was classified as critical, was found in MitraStar GPT-2541GNAC BR_g5.6_1.11(WVK.0)b26. Affected is an unknown function of the file /cgi-bin/settings-firewall.cgi of the component Firewall Settings Page. The manipulation of the argument SrcInterface leads to os command injectโ€ฆ

๐Ÿ“… Published: Oct. 15, 2024, 12:31 p.m. ๐Ÿ”„ Last Modified: Oct. 16, 2024, 4:38 p.m.

5.3

CVSS4.0

CVE-2024-9976 - code-projects Pharmacy Management System manage_customer.php sql injection

A vulnerability classified as critical has been found in code-projects Pharmacy Management System 1.0. This affects an unknown part of the file /php/manage_customer.php?action=search. The manipulation of the argument text leads to sql injection. It is possible to initiate the attack remotely. The eโ€ฆ

๐Ÿ“… Published: Oct. 15, 2024, 11 a.m. ๐Ÿ”„ Last Modified: Oct. 16, 2024, 1:42 p.m.
Total resulsts: 343944
Page 7766 of 34,395
ยซ previous page ยป next page
Filters