8.7

CVSS4.0

CVE-2024-8924 - Unauthenticated Blind SQL Injection in Core Platform

ServiceNow has addressed a blind SQL injection vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to extract unauthorized information.ย ServiceNow deployed an update to hosted instances, and ServiceNow provided the update to our partners anโ€ฆ

๐Ÿ“… Published: Oct. 29, 2024, 4:14 p.m. ๐Ÿ”„ Last Modified: Nov. 27, 2024, 7:32 p.m.

9.3

CVSS4.0

CVE-2024-8923 - Sandbox Escape in Now Platform

ServiceNow has addressed an input validation vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform.ย ServiceNow deployed an update to hosted instances and ServiceNow provided the โ€ฆ

๐Ÿ“… Published: Oct. 29, 2024, 4:07 p.m. ๐Ÿ”„ Last Modified: Nov. 27, 2024, 7:31 p.m.

5.1

CVSS4.0

CVE-2024-25566 - Open Redirect in PingAM

An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect URLs. This could allow an attacker to redirect end-users to malicious sites under their control, simplifying phishing attacks

๐Ÿ“… Published: Oct. 29, 2024, 3:34 p.m. ๐Ÿ”„ Last Modified: Nov. 8, 2024, 3:38 p.m.

7.5

CVSS3.1

CVE-2024-7985 - FileOrganizer <= 1.0.9 - Authenticated (Subscriber+) Arbitrary File Upload

The FileOrganizer โ€“ Manage WordPress and Website Files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the "fileorganizer_ajax_handler" function in all versions up to, and including, 1.0.9. This makes it possible for authenticated attackers, with โ€ฆ

๐Ÿ“… Published: Oct. 29, 2024, 3:31 p.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:33 p.m.

2.2

CVSS3.1

CVE-2024-10452 - grafana: Org admin can delete pending invites in different org

Organization admins can delete pending invites created in an organization they are not part of.

๐Ÿ“… Published: Oct. 29, 2024, 3:16 p.m. ๐Ÿ”„ Last Modified: Nov. 8, 2024, 5:59 p.m.

8.7

CVSS4.0

CVE-2024-50334 - Semicolon Path Injection on API /api;/config

Scoold is a Q&A and a knowledge sharing platform for teams. A semicolon path injection vulnerability was found on the /api;/config endpoint. By appending a semicolon in the URL, attackers can bypass authentication and gain unauthorised access to sensitive configuration data. Furthermore, PUT requesโ€ฆ

๐Ÿ“… Published: Oct. 29, 2024, 2:36 p.m. ๐Ÿ”„ Last Modified: Nov. 8, 2024, 7:51 p.m.

9.1

CVSS3.1

CVE-2024-49768 - Waitress has request processing race condition in HTTP pipelining with invalid first request

Waitress is a Web Server Gateway Interface server for Python 2 and 3. A remote client may send a request that is exactly recv_bytes (defaults to 8192) long, followed by a secondary request using HTTP pipelining. When request lookahead is disabled (default) we won't read any more requests, and when โ€ฆ

๐Ÿ“… Published: Oct. 29, 2024, 2:32 p.m. ๐Ÿ”„ Last Modified: Nov. 7, 2024, 5:28 p.m.

7.5

CVSS3.1

CVE-2024-49769 - Waitress has a denial of service leading to high CPU usage/resource exhaustion

Waitress is a Web Server Gateway Interface server for Python 2 and 3. When a remote client closes the connection before waitress has had the opportunity to call getpeername() waitress won't correctly clean up the connection leading to the main thread attempting to write to a socket that no longer eโ€ฆ

๐Ÿ“… Published: Oct. 29, 2024, 2:18 p.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:41 a.m.

8.7

CVSS4.0

CVE-2024-48921 - Kyverno's PolicyException objects can be created in any namespace by default

Kyverno is a policy engine designed for Kubernetes. A kyverno ClusterPolicy, ie. "disallow-privileged-containers," can be overridden by the creation of a PolicyException in a random namespace. By design, PolicyExceptions are consumed from any namespace. Administrators may not recognize that this alโ€ฆ

๐Ÿ“… Published: Oct. 29, 2024, 2:14 p.m. ๐Ÿ”„ Last Modified: Nov. 7, 2024, 5:20 p.m.

6.4

CVSS3.1

CVE-2024-10226 - Arconix Shortcodes <= 2.1.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via box Shoโ€ฆ

The Arconix Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'box' shortcode in all versions up to, and including, 2.1.13 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attโ€ฆ

๐Ÿ“… Published: Oct. 29, 2024, 1:53 p.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:09 p.m.
Total resulsts: 349182
Page 8094 of 34,919
ยซ previous page ยป next page
Filters