5.3

CVSS3.1

CVE-2024-47855 - json-lib: Mishandling of an unbalanced comment string in json-lib

util/JSONTokener.java in JSON-lib before 3.1.0 mishandles an unbalanced comment string.

๐Ÿ“… Published: Oct. 4, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS3.1

CVE-2024-47191 - oath-toolkit: Local root exploit in a PAM module

pam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because, in the context of PAM code running as root, it mishandles usersfile access, such as by calling fchown in the presence of a symlink.

๐Ÿ“… Published: Oct. 4, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-47913 -

An issue was discovered in the AbuseFilter extension for MediaWiki before 1.39.9, 1.40.x and 1.41.x before 1.41.3, and 1.42.x before 1.42.2. An API caller can match a filter condition against AbuseFilter logs even if the caller is not authorized to view the log details for the filter.

๐Ÿ“… Published: Oct. 4, 2024, midnight ๐Ÿ”„ Last Modified: June 17, 2025, 3:54 p.m.

5.4

CVSS3.1

CVE-2024-41516 -

A Reflected cross-site scripting (XSS) vulnerability in "ccHandler.aspx" CADClick <= 1.11.0 allows remote attackers to inject arbitrary web script or HTML via the "bomid" parameter.

๐Ÿ“… Published: Oct. 4, 2024, midnight ๐Ÿ”„ Last Modified: June 2, 2025, 5:40 p.m.

9.8

CVSS3.1

CVE-2023-26770 -

TaskCafe 0.3.2 lacks validation in the Cookie value. Any unauthenticated attacker who knows a registered UserID can change the password of that user.

๐Ÿ“… Published: Oct. 4, 2024, midnight ๐Ÿ”„ Last Modified: May 27, 2025, 7:18 p.m.

7.5

CVSS3.1

CVE-2024-47850 - cups-browsed: cups-filters: cups-browsed vulnerable to DDoS amplification attack

CUPS cups-browsed before 2.5b1 will send an HTTP POST request to an arbitrary destination and port in response to a single IPP UDP packet requesting a printer to be added, a different vulnerability than CVE-2024-47176. (The request is meant to probe the new printer but can be used to create DDoS amโ€ฆ

๐Ÿ“… Published: Oct. 4, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-41512 -

A SQL Injection vulnerability in "ccHandler.aspx" in all versions of CADClick v.1.11.0 and before allows remote attackers to execute arbitrary SQL commands via the "bomid" parameter.

๐Ÿ“… Published: Oct. 4, 2024, midnight ๐Ÿ”„ Last Modified: June 2, 2025, 5:40 p.m.

8

CVSS3.1

CVE-2024-46486 -

TP-LINK TL-WDR5620 v2.3 was discovered to contain a remote code execution (RCE) vulnerability via the httpProcDataSrv function.

๐Ÿ“… Published: Oct. 4, 2024, midnight ๐Ÿ”„ Last Modified: Aug. 15, 2025, 8:39 p.m.

6.5

CVSS3.1

CVE-2023-26771 -

Taskcafe 0.3.2 is vulnerable to Cross Site Scripting (XSS). There is a lack of validation in the filetype when uploading a SVG profile picture with a XSS payload on it. An authenticated attacker can exploit this vulnerability by uploading a malicious picture which will trigger the payload when the โ€ฆ

๐Ÿ“… Published: Oct. 4, 2024, midnight ๐Ÿ”„ Last Modified: May 27, 2025, 7:26 p.m.

5.4

CVSS3.1

CVE-2024-46409 -

A stored cross-site scripting (XSS) vulnerability in SeedDMS v6.0.28 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter in the Calendar page.

๐Ÿ“… Published: Oct. 4, 2024, midnight ๐Ÿ”„ Last Modified: July 3, 2025, 2:13 p.m.
Total resulsts: 349182
Page 8406 of 34,919
ยซ previous page ยป next page
Filters