9.8

CVSS3.1

CVE-2024-42509 - Unauthenticated Command Injection Vulnerability in the CLI Service Accessed by the PAPI Protocol

Command injection vulnerability in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the abilit…

πŸ“… Published: Nov. 5, 2024, 10:34 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.3

CVSS4.0

CVE-2024-51756 - cap-std doesn't fully sandbox all the Windows device filenames

The cap-std project is organized around the eponymous `cap-std` crate, and develops libraries to make it easy to write capability-based code. cap-std's filesystem sandbox implementation on Windows blocks access to special device filenames such as "COM1", "COM2", "LPT0", "LPT1", and so on, however i…

πŸ“… Published: Nov. 5, 2024, 10:06 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-10084 - Contact Form 7 – Dynamic Text Extension <= 4.5 - Information Disclosure via Shortcode

The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Basic Information Disclosure in all versions up to, and including, 4.5 via the CF7_get_post_var shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract the ti…

πŸ“… Published: Nov. 5, 2024, 9:29 p.m. πŸ”„ Last Modified: April 8, 2026, 5:28 p.m.

2.3

CVSS4.0

CVE-2024-51745 - Wasmtime doesn't fully sandbox all the Windows device filenames

Wasmtime is a fast and secure runtime for WebAssembly. Wasmtime's filesystem sandbox implementation on Windows blocks access to special device filenames such as "COM1", "COM2", "LPT0", "LPT1", and so on, however it did not block access to the special device filenames which use superscript digits, s…

πŸ“… Published: Nov. 5, 2024, 9:09 p.m. πŸ”„ Last Modified: Sept. 4, 2025, 4:14 p.m.

7.8

CVSS3.1

CVE-2024-7995 - Autodesk VRED Design Privilege Escalation Vulnerability

A maliciously crafted binary file when downloaded could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to an untrusted search path being utilized in the VRED Design application. Exploitation of this vulnerability may lead to code execution.

πŸ“… Published: Nov. 5, 2024, 8:06 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 6:27 p.m.

2.1

CVSS4.0

CVE-2024-51752 - Refresh tokens are logged when the debug flag is enabled in @workos-inc/authkit-nextjs

The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & AuthKit with Next.js. In affected versions refresh tokens are logged to the console when the disabled by default `debug` flag, is enabled. This issue has been patched in version 0.13…

πŸ“… Published: Nov. 5, 2024, 7:16 p.m. πŸ”„ Last Modified: Dec. 11, 2025, 5:45 p.m.

2.1

CVSS4.0

CVE-2024-51753 - Refresh tokens are logged when the debug flag is enabled in @workos-inc/authkit-remix

The AuthKit library for Remix provides convenient helpers for authentication and session management using WorkOS & AuthKit with Remix. In affected versions refresh tokens are logged to the console when the disabled by default `debug` flag, is enabled. This issue has been patched in version 0.4.1. A…

πŸ“… Published: Nov. 5, 2024, 7:14 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

1.8

CVSS4.0

CVE-2024-51746 - Use of incorrect Rekor entries during verification in gitsign

Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. gitsign may select the wrong Rekor entry to use during online verification when multiple entries are returned by the log. gitsign uses Rekor's search API to fetch entries that apply to a signature bein…

πŸ“… Published: Nov. 5, 2024, 6:54 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2024-51735 - Stored Cross-site Scripting to RCE on Osmedeus Web Server

Osmedeus is a Workflow Engine for Offensive Security. Cross-site Scripting (XSS) occurs on the Osmedues web server when viewing results from the workflow, allowing commands to be executed on the server. When using a workflow that contains the summary module, it generates reports in HTML and Markdow…

πŸ“… Published: Nov. 5, 2024, 6:49 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.9

CVSS3.1

CVE-2024-50335 - Authenticated XSS in "Publish Key" Field Allowing Unauthorized Administrator User Creation in Suite…

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. The "Publish Key" field in SuiteCRM's Edit Profile page is vulnerable to Reflected Cross-Site Scripting (XSS), allowing an attacker to inject malicious JavaScript code. This can be exploited to…

πŸ“… Published: Nov. 5, 2024, 6:42 p.m. πŸ”„ Last Modified: Nov. 8, 2024, 3:09 p.m.
Total resulsts: 349182
Page 8011 of 34,919
Β« previous page Β» next page
Filters