5.4

CVSS3.1

CVE-2024-51987 - HTTP Client uses incorrect token after refresh in Duende.AccessTokenManagement.OpenIdConnect

Duende.AccessTokenManagement.OpenIdConnect is a set of .NET libraries that manage OAuth and OpenId Connect access tokens. HTTP Clients created by `AddUserAccessTokenHttpClient` may use a different user's access token after a token refresh occurs. This occurs because a refreshed token will be capturโ€ฆ

๐Ÿ“… Published: Nov. 7, 2024, 11:36 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS3.1

CVE-2024-51998 - Path traversal using file URI scheme without supplying hostname in changedetection.io

changedetection.io is a free open source web page change detection tool. The validation for the file URI scheme falls short, and results in an attacker being able to read any file on the system. This issue only affects instances with a webdriver enabled, and `ALLOW_FILE_URI` false or not defined. Tโ€ฆ

๐Ÿ“… Published: Nov. 7, 2024, 11:34 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2024-8424 - WatchGuard Endpoint Protection Privilege Escalation in PSANHost Enables Arbitrary File Delete as SYโ€ฆ

Improper Privilege Management vulnerability in WatchGuard EPDR, Panda AD360 and Panda Dome on Windows (PSANHost.exe module) allows arbitrary file delete with SYSTEM permissions. This issue affects EPDR: before 8.00.23.0000; Panda AD360: before 8.00.23.0000; Panda Dome: before 22.03.00.

๐Ÿ“… Published: Nov. 7, 2024, 11:27 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-49523 - Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victimโ€™s browser when they browse to the pageโ€ฆ

๐Ÿ“… Published: Nov. 7, 2024, 9:35 p.m. ๐Ÿ”„ Last Modified: Dec. 2, 2024, 10:44 p.m.

5.4

CVSS3.1

CVE-2024-49524 - Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)

Adobe Experience Manager versions 6.5.20 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DOM element through a crafted URL or user inpuโ€ฆ

๐Ÿ“… Published: Nov. 7, 2024, 9:35 p.m. ๐Ÿ”„ Last Modified: Dec. 2, 2024, 10:44 p.m.

8.7

CVSS4.0

CVE-2024-8810 - Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed GitHub Aโ€ฆ

A GitHub App installed in organizations could upgrade some permissions from read to write access without approval from an organization administrator. An attacker would require an account with administrator access to install a malicious GitHub App. This vulnerability affected all versions of GitHub โ€ฆ

๐Ÿ“… Published: Nov. 7, 2024, 9:24 p.m. ๐Ÿ”„ Last Modified: Aug. 27, 2025, 4:33 p.m.

6

CVSS4.0

CVE-2024-10824 - Authorization Bypass Vulnerability was Identified in GitHub Enterprise Server that Allowed Unauthorโ€ฆ

An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed unauthorized internal users to access sensitive secret scanning alert data intended only for business owners. This issue could be exploited only by organization members with a personal access token (PAT) aโ€ฆ

๐Ÿ“… Published: Nov. 7, 2024, 9:15 p.m. ๐Ÿ”„ Last Modified: Aug. 27, 2025, 4:27 p.m.

7.7

CVSS3.1

CVE-2024-10975 - Nomad Vulnerable To Cross-Namespace Volume Creation Abusing CSI Write Permission

Nomad Community and Nomad Enterprise ("Nomad") volume specification is vulnerable to arbitrary cross-namespace volume creation through unauthorized Container Storage Interface (CSI) volume writes. This vulnerability, identified as CVE-2024-10975, is fixed in Nomad Community Edition 1.9.2 and Nomad โ€ฆ

๐Ÿ“… Published: Nov. 7, 2024, 9:04 p.m. ๐Ÿ”„ Last Modified: Dec. 29, 2025, 5:17 p.m.

8.7

CVSS4.0

CVE-2024-10007 - Pre-Receive Hook Path Collision Vulnerability in GitHub Enterprise Server Allowing Privilege Escalaโ€ฆ

A path collision and arbitrary code execution vulnerability was identified in GitHub Enterprise Server that allowed container escape to escalate to root via ghe-firejail path. Exploitation of this vulnerability requires Enterprise Administrator access to the GitHub Enterprise Server instance. This โ€ฆ

๐Ÿ“… Published: Nov. 7, 2024, 8:58 p.m. ๐Ÿ”„ Last Modified: Aug. 27, 2025, 4:32 p.m.

6.9

CVSS4.0

CVE-2024-10969 - 1000 Projects Bookstore Management System Login login_process.php sql injection

A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/login_process.php of the component Login. The manipulation of the argument unm/pwd leads to sql injection. The attack maโ€ฆ

๐Ÿ“… Published: Nov. 7, 2024, 8 p.m. ๐Ÿ”„ Last Modified: Sept. 30, 2025, 2:40 p.m.
Total resulsts: 347742
Page 7846 of 34,775
ยซ previous page ยป next page
Filters