6.1

CVSS3.1

CVE-2024-42834 -

A stored cross-site scripting (XSS) vulnerability in the Create Customer API in Incognito Service Activation Center (SAC) UI v14.11 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the lastName parameter.

πŸ“… Published: Nov. 13, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-40443 -

SQL Injection vulnerability in Simple Laboratory Management System using PHP and MySQL v.1.0 allows a remote attacker to cause a denial of service via the delete_users function in the Useres.php

πŸ“… Published: Nov. 13, 2024, midnight πŸ”„ Last Modified: April 16, 2025, 3:06 p.m.

8.8

CVSS3.1

CVE-2024-50853 -

Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetDebugCfg function.

πŸ“… Published: Nov. 13, 2024, midnight πŸ”„ Last Modified: Nov. 21, 2024, 5:15 p.m.

8.8

CVSS3.1

CVE-2024-50852 -

Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetUSBPartitionUmount function.

πŸ“… Published: Nov. 13, 2024, midnight πŸ”„ Last Modified: Nov. 21, 2024, 5:15 p.m.

6.3

CVSS4.0

CVE-2024-11168 - Improper validation of IPv6 and IPvFuture addresses

The urllib.parse.urlsplit() and urlparse() functions improperly validated bracketed hosts (`[]`), allowing hosts that weren't IPv6 or IPvFuture. This behavior was not conformant to RFC 3986 and potentially enabled SSRF if a URL is processed by more than one URL parser.

πŸ“… Published: Nov. 12, 2024, 9:22 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2024-49510 - InDesign Desktop | Out-of-bounds Read (CWE-125)

InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in tha…

πŸ“… Published: Nov. 12, 2024, 8:45 p.m. πŸ”„ Last Modified: Nov. 16, 2024, 12:35 a.m.

5.5

CVSS3.1

CVE-2024-49512 - InDesign Desktop | Out-of-bounds Read (CWE-125)

InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in tha…

πŸ“… Published: Nov. 12, 2024, 8:45 p.m. πŸ”„ Last Modified: Nov. 16, 2024, 12:34 a.m.

7.8

CVSS3.1

CVE-2024-49509 - InDesign Desktop | Heap-based Buffer Overflow (CWE-122)

InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

πŸ“… Published: Nov. 12, 2024, 8:45 p.m. πŸ”„ Last Modified: Nov. 16, 2024, 12:35 a.m.

5.5

CVSS3.1

CVE-2024-49511 - InDesign Desktop | Out-of-bounds Read (CWE-125)

InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in tha…

πŸ“… Published: Nov. 12, 2024, 8:45 p.m. πŸ”„ Last Modified: Nov. 16, 2024, 12:34 a.m.

7.8

CVSS3.1

CVE-2024-49507 - InDesign Desktop | Heap-based Buffer Overflow (CWE-122)

InDesign Desktop versions ID18.5.2, ID19.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

πŸ“… Published: Nov. 12, 2024, 8:45 p.m. πŸ”„ Last Modified: Nov. 16, 2024, 12:33 a.m.
Total resulsts: 349182
Page 7909 of 34,919
Β« previous page Β» next page
Filters