6.5

CVSS3.1

CVE-2024-39437 -

In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed.

πŸ“… Published: Oct. 9, 2024, 6:43 a.m. πŸ”„ Last Modified: Oct. 17, 2024, 5:18 p.m.

6.5

CVSS3.1

CVE-2024-39436 -

In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed.

πŸ“… Published: Oct. 9, 2024, 6:43 a.m. πŸ”„ Last Modified: Oct. 17, 2024, 5:16 p.m.

4.8

CVSS3.1

CVE-2024-5968 - Photo Gallery by 10Web <= 1.8.27 - Admin+ Stored XSS

The Photo Gallery by 10Web WordPress plugin before 1.8.28 does not properly sanitise and escape some of its Gallery settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in m…

πŸ“… Published: Oct. 9, 2024, 6 a.m. πŸ”„ Last Modified: May 6, 2025, 6:21 p.m.

6.4

CVSS3.1

CVE-2024-7963 - CMSMasters Content Composer <= 1.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via…

The CMSMasters Content Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's multiple shortcodes in all versions up to, and including, 1.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authe…

πŸ“… Published: Oct. 9, 2024, 2:01 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-6861 - Foreman: foreman: oauth secret exposure via unauthenticated access to the graphql api

A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is enabled, it is possible for attackers to retrieve sensitive admin authentication keys which could result in a compromise of the entire product's API.

πŸ“… Published: Oct. 9, 2024, 12:42 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2023-46586 -

cgi.c in weborf .0.17, 0.18, 0.19, and 0.20 (before 1.0) lacks '\0' termination of the path for CGI scripts because strncpy is misused.

πŸ“… Published: Oct. 9, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-46304 -

A NULL pointer dereference in libcoap v4.3.5-rc2 and below allows a remote attacker to cause a denial of service via the coap_handle_request_put_block function in src/coap_block.c.

πŸ“… Published: Oct. 9, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-46292 - mod_security: denial of service via name paramter

A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name parameter. NOTE: this is disputed by the Supplier because it cannot be reproduced. Also, the product's documentation indicates that it is not guaranteed to be usab…

πŸ“… Published: Oct. 9, 2024, midnight πŸ”„ Last Modified: June 17, 2025, 3:49 p.m.

9.1

CVSS3.1

CVE-2024-45160 -

Incorrect credential validation in LemonLDAP::NG 2.18.x and 2.19.x before 2.19.2 allows attackers to bypass OAuth2 client authentication via an empty client_password parameter (client secret).

πŸ“… Published: Oct. 9, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-47659 - smack: tcp: ipv4, fix incorrect labeling

In the Linux kernel, the following vulnerability has been resolved: smack: tcp: ipv4, fix incorrect labeling Currently, Smack mirrors the label of incoming tcp/ipv4 connections: when a label 'foo' connects to a label 'bar' with tcp/ipv4, 'foo' always gets 'foo' in returned ipv4 packets. So, 1) re…

πŸ“… Published: Oct. 9, 2024, midnight πŸ”„ Last Modified: Jan. 5, 2026, 10:53 a.m.
Total resulsts: 349182
Page 8343 of 34,919
Β« previous page Β» next page
Filters