5.3

CVSS4.0

CVE-2024-10597 - ESAFENET CDG PolicyActionService.java delPolicyAction sql injection

A vulnerability classified as critical has been found in ESAFENET CDG 5. This affects the function delPolicyAction of the file /com/esafenet/servlet/system/PolicyActionService.java. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The explo…

πŸ“… Published: Oct. 31, 2024, 9 p.m. πŸ”„ Last Modified: Nov. 6, 2024, 4:28 p.m.

5.3

CVSS4.0

CVE-2024-10596 - ESAFENET CDG EncryptPolicyTypeService.java delEntryptPolicySort sql injection

A vulnerability was found in ESAFENET CDG 5. It has been rated as critical. Affected by this issue is the function delEntryptPolicySort of the file /com/esafenet/servlet/system/EncryptPolicyTypeService.java. The manipulation of the argument id leads to sql injection. The attack may be launched remo…

πŸ“… Published: Oct. 31, 2024, 9 p.m. πŸ”„ Last Modified: Nov. 5, 2024, 4:20 p.m.

5.3

CVSS4.0

CVE-2024-10595 - ESAFENET CDG PublicDocInfoAjax.java delDifferCourseList sql injection

A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. Affected by this vulnerability is the function delFile/delDifferCourseList of the file /com/esafenet/servlet/ajax/PublicDocInfoAjax.java. The manipulation leads to sql injection. The attack can be launched remotely. The …

πŸ“… Published: Oct. 31, 2024, 8:31 p.m. πŸ”„ Last Modified: Nov. 1, 2024, 8:57 p.m.

5.3

CVSS4.0

CVE-2024-10594 - ESAFENET CDG FileDirectoryService.java docHistory sql injection

A vulnerability was found in ESAFENET CDG 5. It has been classified as critical. Affected is the function docHistory of the file /com/esafenet/servlet/fileManagement/FileDirectoryService.java. The manipulation of the argument fileId leads to sql injection. It is possible to launch the attack remote…

πŸ“… Published: Oct. 31, 2024, 8:31 p.m. πŸ”„ Last Modified: Nov. 5, 2024, 5:05 p.m.

10

CVSS3.1

CVE-2024-51482 - Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64

ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder v1.37.* <= 1.37.64 is vulnerable to boolean-based SQL Injection in function of web/ajax/event.php. This is fixed in 1.37.65.

πŸ“… Published: Oct. 31, 2024, 6:07 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0

CVSS3.1

CVE-2024-50356 - Press has a potential 2FA bypass

Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). The password could be reset by anyone who have access to the mail inbox circumventing the 2FA. Even though they wouldn't be able to login by bypassing the 2FA. Onl…

πŸ“… Published: Oct. 31, 2024, 6:02 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS4.0

CVE-2024-50347 - Laravel Reverb has Missing API Signature Verification

Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. Prior to 1.4.0, there is an issue where verification signatures for requests sent to Reverb's Pusher-compatible API were not being verified. This API is used in scenarios such as broadcasting a message fro…

πŸ“… Published: Oct. 31, 2024, 5:56 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.7

CVSS3.1

CVE-2024-7883 - CMSE secure state may leak from stack to floating-point registers

When using Arm Cortex-M Security Extensions (CMSE), Secure stack contents can be leaked to Non-secure state via floating-point registers when a Secure to Non-secure function call is made that returns a floating-point value and when this is the first use of floating-point since entering Secure s…

πŸ“… Published: Oct. 31, 2024, 5:01 p.m. πŸ”„ Last Modified: Dec. 23, 2025, 3:30 p.m.

9.9

CVSS3.1

CVE-2024-51478 - Use of a Broken or Risky Cryptographic Algorithm in YesWiki

YesWiki is a wiki system written in PHP. Prior to 4.4.5, the use of a weak cryptographic algorithm and a hard-coded salt to hash the password reset key allows it to be recovered and used to reset the password of any account. This issue is fixed in 4.4.5.

πŸ“… Published: Oct. 31, 2024, 4:15 p.m. πŸ”„ Last Modified: May 9, 2025, 2:06 p.m.

1

CVSS4.0

CVE-2024-51481 - Nix allows macOS sandbox escape via built-in builders

Nix is a package manager for Linux and other Unix systems. On macOS, built-in builders (such as `builtin:fetchurl`, exposed to users with `import <nix/fetchurl.nix>`) were not executed in the macOS sandbox. Thus, these builders (which are running under the `nixbld*` users) had read access to world-…

πŸ“… Published: Oct. 31, 2024, 4:10 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 8074 of 34,919
Β« previous page Β» next page
Filters