5.5

CVSS3.1

CVE-2024-50354 - Out-of-memory during deserialization with crafted inputs

gnark is a fast zk-SNARK library that offers a high-level API to design circuits. In gnark 0.11.0 and earlier, deserialization of Groth16 verification keys allocate excessive memory, consuming a lot of resources and triggering a crash with the error fatal error: runtime: out of memory.

πŸ“… Published: Oct. 31, 2024, 3:59 p.m. πŸ”„ Last Modified: Sept. 23, 2025, 2 a.m.

7.5

CVSS3.1

CVE-2024-8185 - Vault Vulnerable to Denial of Service When Processing Raft Join Requests

Vault Community and Vault Enterprise (β€œVault”) clusters using Vault’s Integrated Storage backend are vulnerable to a denial-of-service (DoS) attack through memory exhaustion through a Raft cluster join API endpoint . An attacker may send a large volume of requests to the endpoint which may cause Va…

πŸ“… Published: Oct. 31, 2024, 3:14 p.m. πŸ”„ Last Modified: Nov. 13, 2025, 5:40 p.m.

6.3

CVSS3.1

CVE-2024-8553 - Foreman: read-only access to entire db from templates

A vulnerability was found in Foreman's loader macros introduced with report templates. These macros may allow an authenticated user with permissions to view and create templates to read any field from Foreman's database. By using specific strings in the loader macros, users can bypass permissions a…

πŸ“… Published: Oct. 31, 2024, 2:29 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2024-48910 - DOMPurify vulnerable to tampering by prototype polution

DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify was vulnerable to prototype pollution. This vulnerability is fixed in 2.4.2.

πŸ“… Published: Oct. 31, 2024, 2:22 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 9:16 p.m.

6.1

CVSS3.1

CVE-2024-10454 - Clickjacking vulnerability in Clibo Manager

Clickjacking vulnerability in Clibo Manager v1.1.9.12 in the '/public/login' directory, a login panel. This vulnerability occurs due to the absence of an X-Frame-Options server-side header. An attacker could overlay a transparent iframe to perform click hijacking on victims.

πŸ“… Published: Oct. 31, 2024, 12:54 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-8934 - Beckhoff: Local command injection via TwinCAT Package Manager

A local user with administrative access rights can enter specialy crafted values for settings at the user interface (UI) of the TwinCAT Package Manager which then causes arbitrary OS commands to be executed.

πŸ“… Published: Oct. 31, 2024, 12:44 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-43930 - WordPress JobSearch WP Job Board WordPress Plugin plugin <= 2.5.3 - Broken Access Control vulnerabi…

Cross-Site Request Forgery (CSRF) vulnerability in eyecix JobSearch allows Cross Site Request Forgery.This issue affects JobSearch: from n/a through 2.5.3.

πŸ“… Published: Oct. 31, 2024, 10:05 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS3.1

CVE-2024-43933 - WordPress WPMobile.App plugin <= 11.48 - CSRF to Stored XSS vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amauri WPMobile.App wpappninja allows Stored XSS.This issue affects WPMobile.App: from n/a through <= 11.48.

πŸ“… Published: Oct. 31, 2024, 10:04 a.m. πŸ”„ Last Modified: April 23, 2026, 3:18 p.m.

9.6

CVSS3.1

CVE-2024-43984 - WordPress Podlove Podcast Publisher plugin <= 4.1.13 - CSRF to Remote Code Execution (RCE) vulnerab…

Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher allows Code Injection.This issue affects Podlove Podcast Publisher: from n/a through 4.1.13.

πŸ“… Published: Oct. 31, 2024, 10:02 a.m. πŸ”„ Last Modified: March 19, 2025, 5:13 p.m.

9.6

CVSS3.1

CVE-2024-49674 - WordPress EKC Tournament Manager plugin <= 2.2.1 - CSRF to Arbitrary File Upload vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in lukashuser EKC Tournament Manager ekc-tournament-manager allows Upload a Web Shell to a Web Server.This issue affects EKC Tournament Manager: from n/a through <= 2.2.1.

πŸ“… Published: Oct. 31, 2024, 10:01 a.m. πŸ”„ Last Modified: April 23, 2026, 3:19 p.m.
Total resulsts: 349182
Page 8075 of 34,919
Β« previous page Β» next page
Filters