9.8

CVSS3.1

CVE-2024-48411 -

itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to SQL Injection (SQLI) via a crafted payload to the val-email parameter in forget_password.php.

๐Ÿ“… Published: Oct. 15, 2024, midnight ๐Ÿ”„ Last Modified: May 17, 2025, 1:37 a.m.

4.8

CVSS3.1

CVE-2024-48948 - elliptic: ECDSA signature verification error may reject legitimate transactions

The Elliptic package 6.5.7 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if the hash contains at least four leading 0 bytes and when the order of the elliptic curve's base point is smaller than the hash, because of an _truncateToN anomaly. This leads to vaโ€ฆ

๐Ÿ“… Published: Oct. 15, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 25, 2025, 4:16 p.m.

6.5

CVSS3.1

CVE-2024-48714 -

In TP-Link TL-WDR7660 v1.0, the guestRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.

๐Ÿ“… Published: Oct. 15, 2024, midnight ๐Ÿ”„ Last Modified: May 21, 2025, 8:27 p.m.

7.2

CVSS3.1

CVE-2024-9548 - Slimstat Analytics <= 5.2.6 - Unauthenticated Stored Cross-Site Scripting

The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the resource parameter in all versions up to, and including, 5.2.6 due to insufficient input sanitization and output escaping when logging visitor requests. This makes it possible for unauthenticated attackโ€ฆ

๐Ÿ“… Published: Oct. 14, 2024, 11:29 p.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:34 p.m.

5.3

CVSS3.1

CVE-2024-9546 - WPIDE <= 3.4.9 - Unauthenticated Full Path Dislcosure

The WPIDE โ€“ File Manager & Code Editor plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.4.9. This is due to the plugin utilizing the PHP-Parser library, which outputs parser rebuild command execution results. This makes it possible for unauthenticatโ€ฆ

๐Ÿ“… Published: Oct. 14, 2024, 11:29 p.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:30 p.m.

2.5

CVSS3.1

CVE-2024-30117 - HCL BigFix Platform is affected by a DLL Hijack vulnerability

A dynamic search for a prerequisite library could allow the possibility for an attacker to replace the correct file under some circumstances.

๐Ÿ“… Published: Oct. 14, 2024, 10:55 p.m. ๐Ÿ”„ Last Modified: Oct. 17, 2024, 9:01 p.m.

4.9

CVSS3.1

CVE-2024-9953 - Potential DoS Vulnerability in CERT VINCE Software Before Version 3.0.8

A potential denial-of-service (DoS) vulnerability exists in CERT VINCE software versions prior to 3.0.8. An authenticated administrative user can inject an arbitrary pickle object into a userโ€™s profile, which may lead to a DoS condition when the profile is accessed. While the Django server restrictโ€ฆ

๐Ÿ“… Published: Oct. 14, 2024, 9:19 p.m. ๐Ÿ”„ Last Modified: March 20, 2025, 7:15 p.m.

8.7

CVSS4.0

CVE-2024-6207 -

CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html ย and send a specially crafted CIP message to the device. If exploited, a threat actor could help prevent access to the legitimate user and end connections to connected devices including thโ€ฆ

๐Ÿ“… Published: Oct. 14, 2024, 8:53 p.m. ๐Ÿ”„ Last Modified: Oct. 21, 2024, 1:20 p.m.

5.8

CVSS4.0

CVE-2024-48911 - OpenCanary Executes Commands From Potentially Writable Config File

OpenCanary, a multi-protocol network honeypot, directly executed commands taken from its config file. Prior to version 0.9.4, where the config file is stored in an unprivileged user directory but the daemon is executed by root, itโ€™s possible for the unprivileged user to change the config file and eโ€ฆ

๐Ÿ“… Published: Oct. 14, 2024, 8:45 p.m. ๐Ÿ”„ Last Modified: Oct. 17, 2024, 9:13 p.m.

2

CVSS3.1

CVE-2024-48909 - SpiceDB calls to LookupResources using LookupResources2 with caveats may return context is missing โ€ฆ

SpiceDB is an open source database for scalably storing and querying fine-grained authorization data. Starting in version 1.35.0 and prior to version 1.37.1, clients that have enabled `LookupResources2` and have caveats in the evaluation path for their requests can return a permissionship of `CONDIโ€ฆ

๐Ÿ“… Published: Oct. 14, 2024, 8:22 p.m. ๐Ÿ”„ Last Modified: Oct. 17, 2024, 5:56 p.m.
Total resulsts: 349182
Page 8297 of 34,919
ยซ previous page ยป next page
Filters