8.4

CVSS3.1

CVE-2024-9158 - XSS

A stored cross site scripting vulnerability exists in Nessus Network Monitor where an authenticated, privileged local attacker could inject arbitrary code into the NNM UI via the local CLI.

๐Ÿ“… Published: Sept. 30, 2024, 4:24 p.m. ๐Ÿ”„ Last Modified: Oct. 7, 2024, 4:13 p.m.

5.1

CVSS4.0

CVE-2024-47067 - Alist Contains a Reflected Cross-Site Scripting Vulnerability

AList is a file list program that supports multiple storages. AList contains a reflected cross-site scripting vulnerability in helper.go. The endpoint /i/:link_name takes in a user-provided value and reflects it back in the response. The endpoint returns an application/xml response, opening it up tโ€ฆ

๐Ÿ“… Published: Sept. 30, 2024, 3:39 p.m. ๐Ÿ”„ Last Modified: Feb. 13, 2026, 9:18 p.m.

8.7

CVSS4.0

CVE-2024-47532 - RestrictedPython information leakage via `AttributeError.obj` and the `string` module

RestrictedPython is a restricted execution environment for Python to run untrusted code. A user can gain access to protected (and potentially sensible) information indirectly via AttributeError.obj and the string module. The problem will be fixed in version 7.3. As a workaround, If the application โ€ฆ

๐Ÿ“… Published: Sept. 30, 2024, 3:29 p.m. ๐Ÿ”„ Last Modified: Nov. 15, 2024, 5:59 p.m.

4.6

CVSS3.1

CVE-2024-47531 - Scout contains insufficient output escaping of attachment names

Scout is a web-based visualizer for VCF-files. Due to the lack of sanitization in the filename, it is possible bypass intended file extension and make users download malicious files with any extension. With malicious content injected inside the file data and users unknowingly downloading it and opeโ€ฆ

๐Ÿ“… Published: Sept. 30, 2024, 3:26 p.m. ๐Ÿ”„ Last Modified: Nov. 15, 2024, 6:02 p.m.

5.4

CVSS3.1

CVE-2024-47530 - Scout contains an Open Redirect on Login via `next`

Scout is a web-based visualizer for VCF-files. Open redirect vulnerability allows performing phishing attacks on users by redirecting them to malicious page. /login API endpoint is vulnerable to open redirect attack via next parameter due to absence of sanitization logic. Additionally, due to lack โ€ฆ

๐Ÿ“… Published: Sept. 30, 2024, 3:17 p.m. ๐Ÿ”„ Last Modified: Nov. 15, 2024, 6:03 p.m.

8.7

CVSS4.0

CVE-2024-47178 - basic-auth-connect's callback uses time unsafe string comparison

basic-auth-connect is Connect's Basic Auth middleware in its own module. basic-auth-connect < 1.1.0 uses a timing-unsafe equality comparison that can leak timing information. This issue has been fixed in basic-auth-connect 1.1.0.

๐Ÿ“… Published: Sept. 30, 2024, 3:09 p.m. ๐Ÿ”„ Last Modified: Nov. 15, 2024, 6:05 p.m.

5.4

CVSS3.1

CVE-2024-47172 - Computer Vision Annotation Tool (CVAT) access control is broken in several PATCH endpoints

Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with a CVAT account may retrieve certain information about any project, task, job or membership resource on the CVAT instance. The information exposed in this way is the same asโ€ฆ

๐Ÿ“… Published: Sept. 30, 2024, 3 p.m. ๐Ÿ”„ Last Modified: Oct. 30, 2024, 6:20 p.m.

6.3

CVSS4.0

CVE-2024-47064 - Computer Vision Annotation Tool (CVAT) contains a reflected XSS via request endpoints

Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. If an attacker can trick a logged-in CVAT user into visiting a maliciously-constructed URL, they can initiate any API calls on that user's behalf. This gives the attacker temporary access tโ€ฆ

๐Ÿ“… Published: Sept. 30, 2024, 2:57 p.m. ๐Ÿ”„ Last Modified: Oct. 30, 2024, 6:23 p.m.

6.2

CVSS4.0

CVE-2024-47063 - Computer Vision Annotation Tool (CVAT) contains a stored XSS via the quality report data endpoint

Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. If a malicious CVAT user with permissions to either create a task, or edit an existing task can trick another logged-in user into visiting a maliciously-constructed URL, they can initiate aโ€ฆ

๐Ÿ“… Published: Sept. 30, 2024, 2:45 p.m. ๐Ÿ”„ Last Modified: Oct. 30, 2024, 6:24 p.m.

5.3

CVSS4.0

CVE-2024-45792 - MantisBT vulnerable to information disclosure with user profiles

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Using a crafted POST request, an unprivileged, registered user is able to retrieve information about other users' personal system profiles. This vulnerability is fixed in 2.26.4.

๐Ÿ“… Published: Sept. 30, 2024, 2:40 p.m. ๐Ÿ”„ Last Modified: Aug. 15, 2025, 2:09 p.m.
Total resulsts: 349182
Page 8435 of 34,919
ยซ previous page ยป next page
Filters