8.8

CVSS3.1

CVE-2024-52002 - Cross-Site Request Forgery (CSRF) in several iTop pages

Combodo iTop is a simple, web based IT Service Management tool. Several url endpoints are subject to a Cross-Site Request Forgery (CSRF) vulnerability. Please refer to the linked GHSA for the complete list. This issue has been addressed in version 3.2.0 and all users are advised to upgrade. There a…

πŸ“… Published: Nov. 8, 2024, 10:16 p.m. πŸ”„ Last Modified: Jan. 7, 2025, 4:43 p.m.

8.7

CVSS4.0

CVE-2024-52004 - Remote code execution vulnerabilities inΒ MediaCMS

MediaCMS is an open source video and media CMS, written in Python/Django and React, featuring a REST API. MediaCMS has been prone to vulnerabilities that upon special cases can lead to remote code execution. All versions before v4.1.0 are susceptible, and users are highly recommended to upgrade.Β Th…

πŸ“… Published: Nov. 8, 2024, 10:10 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS4.0

CVE-2024-11026 - Intelligent Apps Freenow App Keystore SSL.java hard-coded password

A vulnerability was found in Intelligent Apps Freenow App 12.10.0 on Android. It has been rated as problematic. Affected by this issue is some unknown functionality of the file ch/qos/logback/core/net/ssl/SSL.java of the component Keystore Handler. The manipulation of the argument DEFAULT_KEYSTORE_…

πŸ“… Published: Nov. 8, 2024, 9:31 p.m. πŸ”„ Last Modified: Nov. 23, 2024, 1:44 a.m.

4.3

CVSS3.1

CVE-2024-21994 - CVE-2024-21994 Denial of Service Vulnerability in StorageGRID (formerly StorageGRID Webscale)

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9 are susceptible to a Denial of Service (DoS) vulnerability. Successful exploit by an authenticated attacker could lead to a service crash.

πŸ“… Published: Nov. 8, 2024, 9:06 p.m. πŸ”„ Last Modified: Sept. 23, 2025, 2:33 p.m.

8.1

CVSS3.1

CVE-2024-51997 - The Attestation Results Token can be arbitrarily modified without being detected in Trustee

Trustee is a set of tools and components for attesting confidential guests and providing secrets to them. The ART (**Attestation Results Token**) token, generated by AS, could be manipulated by MITM attacker, but the verifier (CoCo Verification Demander like KBS) could still verify it successfully.…

πŸ“… Published: Nov. 8, 2024, 6:40 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7

CVSS4.0

CVE-2024-9841 - OpenText ArcSight Management Center and ArcSight Platform Stored XSS

A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Management Center and ArcSight Platform. The vulnerability could be remotely exploited.

πŸ“… Published: Nov. 8, 2024, 5:58 p.m. πŸ”„ Last Modified: Nov. 13, 2024, 7:34 p.m.

9.1

CVSS3.1

CVE-2024-45763 -

Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. This i…

πŸ“… Published: Nov. 8, 2024, 4:15 p.m. πŸ”„ Last Modified: Nov. 13, 2024, 6:39 p.m.

9

CVSS3.1

CVE-2024-45764 -

Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) a Missing Critical Step in Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. This is a critical severity vulnerability so De…

πŸ“… Published: Nov. 8, 2024, 4:08 p.m. πŸ”„ Last Modified: Nov. 13, 2024, 7:08 p.m.

8.1

CVSS3.1

CVE-2024-10220 - Arbitrary command execution through gitRepo volume

The Kubernetes kubelet component allows arbitrary command execution via specially crafted gitRepo volumes.This issue affects kubelet: through 1.28.11, from 1.29.0 through 1.29.6, from 1.30.0 through 1.30.2.

πŸ“… Published: Nov. 8, 2024, 4 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2024-45765 -

Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. This i…

πŸ“… Published: Nov. 8, 2024, 3:59 p.m. πŸ”„ Last Modified: Nov. 13, 2024, 7:06 p.m.
Total resulsts: 349182
Page 7978 of 34,919
Β« previous page Β» next page
Filters