9.3

CVSS4.0

CVE-2024-47073 - Dataease arbitrary interface access vulnerability

DataEase is an open source data visualization analysis tool that helps users quickly analyze data and gain insights into business trends. In affected versions a the lack of signature verification of jwt tokens allows attackers to forge jwts which then allow access to any interface. The vulnerabilit…

πŸ“… Published: Nov. 7, 2024, 5:31 p.m. πŸ”„ Last Modified: Feb. 20, 2025, 4:20 p.m.

5.3

CVSS4.0

CVE-2024-10965 - emqx neuron JSON File schema information disclosure

A vulnerability classified as problematic was found in emqx neuron up to 2.10.0. Affected by this vulnerability is an unknown functionality of the file /api/v2/schema of the component JSON File Handler. The manipulation leads to information disclosure. The attack can be launched remotely. The patch…

πŸ“… Published: Nov. 7, 2024, 5 p.m. πŸ”„ Last Modified: Nov. 23, 2024, 1:45 a.m.

5.3

CVSS4.0

CVE-2024-10964 - emqx neuron plugin_handle.c handle_add_plugin buffer overflow

A vulnerability classified as critical has been found in emqx neuron up to 2.10.0. Affected is the function handle_add_plugin in the library cmd.library of the file plugins/restful/plugin_handle.c. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. It is recomm…

πŸ“… Published: Nov. 7, 2024, 5 p.m. πŸ”„ Last Modified: Nov. 26, 2024, 1:36 a.m.

7.7

CVSS3.0

CVE-2024-40715 -

A vulnerability in Veeam Backup & Replication Enterprise Manager has been identified, which allows attackers to perform authentication bypass. Attackers must be able to perform Man-in-the-Middle (MITM) attack to exploit this vulnerability.

πŸ“… Published: Nov. 7, 2024, 4:40 p.m. πŸ”„ Last Modified: July 11, 2025, 1:57 p.m.

5.9

CVSS4.0

CVE-2024-10668 - Auth Bypass in Quickshare

There exists an auth bypass in Google Quickshare where an attacker can upload an unknown file type to a victim.Β The root cause of the vulnerability lies in the fact that when a Payload Transfer frame of type FILE is sent to Quick Share, the file that is contained in this frame is written to disk in…

πŸ“… Published: Nov. 7, 2024, 3:22 p.m. πŸ”„ Last Modified: July 23, 2025, 7:30 p.m.

4.8

CVSS3.1

CVE-2024-8378 - Safe SVG < 2.2.6 - Author+ SVG Sanitisation Bypass

The Safe SVG WordPress plugin before 2.2.6 has its sanitisation code is only running for paths that call wp_handle_upload, but not for example for code that uses wp_handle_sideload which is often used to upload attachments via raw POST data.

πŸ“… Published: Nov. 7, 2024, 3:07 p.m. πŸ”„ Last Modified: May 17, 2025, 1:45 a.m.

4.3

CVSS3.1

CVE-2024-9926 - Jetpack < 13.9.1 - Subscriber+ Arbitrary Feedback Access

The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact Form

πŸ“… Published: Nov. 7, 2024, 3:02 p.m. πŸ”„ Last Modified: May 28, 2025, 8:51 p.m.

7.5

CVSS3.1

CVE-2024-43438 - Moodle: idor in feedback non-respondents report allows messaging arbitrary site users

A flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients belonging to the set of users returned by the report.

πŸ“… Published: Nov. 7, 2024, 1:31 p.m. πŸ”„ Last Modified: Aug. 5, 2025, 6:36 p.m.

7.2

CVSS3.1

CVE-2024-43436 - Moodle: site administration sql injection via xmldb editor

A SQL injection risk flaw was found in the XMLDB editor tool available to site administrators.

πŸ“… Published: Nov. 7, 2024, 1:29 p.m. πŸ”„ Last Modified: Aug. 5, 2025, 6:34 p.m.

8.1

CVSS3.1

CVE-2024-43434 - Moodle: csrf risk in feedback non-respondents report

The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check, leading to a CSRF vulnerability.

πŸ“… Published: Nov. 7, 2024, 1:28 p.m. πŸ”„ Last Modified: May 1, 2025, 4:03 p.m.
Total resulsts: 347773
Page 7851 of 34,778
Β« previous page Β» next page
Filters