6.3

CVSS3.1

CVE-2024-50652 -

A file upload vulnerability in java_shop 1.0 allows attackers to upload arbitrary files by modifying the avatar function.

πŸ“… Published: Nov. 15, 2024, midnight πŸ”„ Last Modified: Nov. 22, 2024, midnight

6.5

CVSS3.1

CVE-2024-50651 -

java_shop 1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter.

πŸ“… Published: Nov. 15, 2024, midnight πŸ”„ Last Modified: Nov. 27, 2024, 9:15 p.m.

7.8

CVSS3.1

CVE-2024-46466 -

By default, dedicated folders of ZONECENTRAL for Windows up to 2024.3 or up to Q.2021.2 (ANSSI qualification submission) can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of ZONECENTRAL has to be modified to prevent this vulne…

πŸ“… Published: Nov. 15, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-50649 -

The user avatar upload function in python_book V1.0 has an arbitrary file upload vulnerability.

πŸ“… Published: Nov. 15, 2024, midnight πŸ”„ Last Modified: June 17, 2025, 1:15 a.m.

5.3

CVSS3.1

CVE-2024-24450 -

Stack-based memcpy buffer overflow in the ngap_handle_pdu_session_resource_setup_response routine in OpenAirInterface CN5G AMF <= 2.0.0 allows a remote attacker with access to the N2 interface to carry out denial of service against the AMF and potentially execute code by sending a PDU Session Resou…

πŸ“… Published: Nov. 15, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-50983 -

FlightPath 7.5 contains a Cross Site Scripting (XSS) vulnerability, which allows authenticated remote attackers with administrative rights to inject arbitrary JavaScript in the web browser of a user by including a malicious payload into the Last Name section in the Create/Edit Faculty/Staff User or…

πŸ“… Published: Nov. 15, 2024, midnight πŸ”„ Last Modified: July 7, 2025, 4:12 p.m.

7.5

CVSS3.1

CVE-2024-45969 -

NULL pointer dereference in the MMS Client in MZ Automation LibIEC1850 before commit 7afa40390b26ad1f4cf93deaa0052fe7e357ef33 allows a malicious server to Cause a Denial-of-Service via the MMS InitiationResponse message.

πŸ“… Published: Nov. 15, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-24446 -

An uninitialized pointer dereference in OpenAirInterface CN5G AMF up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a crafted InitialContextSetupResponse message sent to the AMF.

πŸ“… Published: Nov. 15, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-45970 -

Multiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit ac925fae8e281ac6defcd630e9dd756264e9c5bc allow a malicious server to cause a stack-based buffer overflow via the MMS FileDirResponse message.

πŸ“… Published: Nov. 15, 2024, midnight πŸ”„ Last Modified: Oct. 1, 2025, 5:45 p.m.

7.3

CVSS3.1

CVE-2024-50986 -

An issue in Clementine v.1.3.1 allows a local attacker to execute arbitrary code via a crafted DLL file.

πŸ“… Published: Nov. 15, 2024, midnight πŸ”„ Last Modified: July 7, 2025, 5:03 p.m.
Total resulsts: 349182
Page 7870 of 34,919
Β« previous page Β» next page
Filters