9.3

CVSS4.0

CVE-2024-47832 - XML Signature Bypass via differential XML parsing in ssoready

ssoready is a single sign on provider implemented via docker. Affected versions are vulnerable to XML signature bypass attacks. An attacker can carry out signature bypass if you have access to certain IDP-signed messages. The underlying mechanism exploits differential behavior between XML parsers. …

πŸ“… Published: Oct. 9, 2024, 6:32 p.m. πŸ”„ Last Modified: Oct. 11, 2024, 4:58 p.m.

2.7

CVSS3.1

CVE-2024-7038 - Information Disclosure in open-webui/open-webui

An information disclosure vulnerability exists in open-webui version 0.3.8. The vulnerability is related to the embedding model update feature under admin settings. When a user updates the model path, the system checks if the file exists and provides different error messages based on the existence …

πŸ“… Published: Oct. 9, 2024, 6:26 p.m. πŸ”„ Last Modified: Nov. 3, 2024, 6:27 p.m.

6.3

CVSS4.0

CVE-2024-47833 - Session Cookie without Secure and HTTPOnly flags in taipy

Taipy is an open-source Python library for easy, end-to-end application development for data scientists and machine learning engineers. In affected versions session cookies are served without Secure and HTTPOnly flags. This issue has been addressed in release version 4.0.0 and all users are advised…

πŸ“… Published: Oct. 9, 2024, 6:25 p.m. πŸ”„ Last Modified: Oct. 16, 2024, 4:33 p.m.

6

CVSS3.1

CVE-2024-47815 - Cross-site Scripting in IncidentReporting

IncidentReporting is a MediaWiki extension for moving incident reports from wikitext to database tables. There are a variety of Cross-site Scripting issues, though all of them require elevated permissions. Some are available to anyone who has the `editincidents` right, some are available to those w…

πŸ“… Published: Oct. 9, 2024, 6:21 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-47816 - Users can impersonate import requesters if their actor IDs coincide in ImportDump

ImportDump is a mediawiki extension designed to automate user import requests. A user's local actor ID is stored in the database to tell who made what requests. Therefore, if a user on another wiki happens to have the same actor ID as someone on the central wiki, the user on the other wiki can act …

πŸ“… Published: Oct. 9, 2024, 6:19 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6

CVSS3.1

CVE-2024-47812 - Cross-site Scripting (XSS) on Special:RequestImportQueue when displaying request date in ImportDump

ImportDump is an extension for mediawiki designed to automate user import requests. Anyone who can edit the interface strings of a wiki (typically administrators and interface admins) can embed XSS payloads in the messages for dates, and thus XSS anyone who views Special:RequestImportQueue. This is…

πŸ“… Published: Oct. 9, 2024, 6:12 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2024-3656 - Keycloak: unguarded admin rest api endpoints allows low privilege users to use administrative funct…

A flaw was found in Keycloak. Certain endpoints in Keycloak's admin REST API allow low-privilege users to access administrative functionalities. This flaw allows users to perform actions reserved for administrators, potentially leading to data breaches or system compromise.

πŸ“… Published: Oct. 9, 2024, 6:11 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.9

CVSS3.1

CVE-2024-47813 - Wasmtime race condition could lead to WebAssembly control-flow integrity and type safety violations

Wasmtime is an open source runtime for WebAssembly. Under certain concurrent event orderings, a `wasmtime::Engine`'s internal type registry was susceptible to double-unregistration bugs due to a race condition, leading to panics and potentially type registry corruption. That registry corruption cou…

πŸ“… Published: Oct. 9, 2024, 6:07 p.m. πŸ”„ Last Modified: Sept. 29, 2025, 1:11 p.m.

5.5

CVSS3.1

CVE-2024-47763 - Wasmtime runtime crash when combining tail calls with trapping imports

Wasmtime is an open source runtime for WebAssembly. Wasmtime's implementation of WebAssembly tail calls combined with stack traces can result in a runtime crash in certain WebAssembly modules. The runtime crash may be undefined behavior if Wasmtime was compiled with Rust 1.80 or prior. The runtime …

πŸ“… Published: Oct. 9, 2024, 6:03 p.m. πŸ”„ Last Modified: Sept. 29, 2025, 1:26 p.m.

5.2

CVSS4.0

CVE-2024-9473 - GlobalProtect App: Local Privilege Escalation (PE) Vulnerability

A privilege escalation vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY/SYSTEM through the use of the repair functionality offered by the .msi file used to install GlobalP…

πŸ“… Published: Oct. 9, 2024, 5:07 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:54 a.m.
Total resulsts: 349182
Page 8336 of 34,919
Β« previous page Β» next page
Filters