6.5

CVSS3.1

CVE-2024-47077 - authentik cross-provider token validation problems

authentik is an open-source identity provider. Prior to versions 2024.8.3 and 2024.6.5, access tokens issued to one application can be stolen by that application and used to impersonate the user against any other proxy provider. Also, a user can steal an access token they were legitimately issued f…

πŸ“… Published: Sept. 27, 2024, 3:26 p.m. πŸ”„ Last Modified: Aug. 21, 2025, 7:28 p.m.

9.1

CVSS3.1

CVE-2024-47070 - authentik vulnerable to password authentication bypass via X-Forwarded-For HTTP header

authentik is an open-source identity provider. A vulnerability that exists in versions prior to 2024.8.3 and 2024.6.5 allows bypassing password login by adding X-Forwarded-For header with an unparsable IP address, e.g. `a`. This results in a possibility of logging into any account with a known logi…

πŸ“… Published: Sept. 27, 2024, 3:18 p.m. πŸ”„ Last Modified: Aug. 21, 2025, 7:28 p.m.

9.2

CVSS4.0

CVE-2024-3373 - SQLi in RSM Design's Website Template

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RSM Design Website Template allows SQL Injection.This issue affects Website Template: before 1.2.

πŸ“… Published: Sept. 27, 2024, 2:14 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-47184 - Ampache vulnerable to Stored XSS via Democratic Playlist Name

Ampache is a web based audio/video streaming application and file manager. Prior to version 6.6.0, the Democratic Playlist Name is vulnerable to a stored cross-site scripting. Version 6.6.0 fixes this issue.

πŸ“… Published: Sept. 27, 2024, 2:05 p.m. πŸ”„ Last Modified: Oct. 4, 2024, 6:19 p.m.

4.8

CVSS4.0

CVE-2024-9283 - RelaxedJS ReLaXed Pug to PDF Converter cross site scripting

A vulnerability classified as problematic has been found in RelaxedJS ReLaXed up to 0.2.2. Affected is an unknown function of the component Pug to PDF Converter. The manipulation leads to cross site scripting. An attack has to be approached locally. The exploit has been disclosed to the public and …

πŸ“… Published: Sept. 27, 2024, 2 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS3.1

CVE-2024-47182 - Dozzle uses unsafe hash for passwords

Dozzle is a realtime log viewer for docker containers. Before version 8.5.3, the app uses sha-256 as the hash for passwords, which leaves users susceptible to rainbow table attacks. The app switches to bcrypt, a more appropriate hash for passwords, in version 8.5.3.

πŸ“… Published: Sept. 27, 2024, 1:58 p.m. πŸ”„ Last Modified: Oct. 4, 2024, 6:31 p.m.

8.8

CVSS3.1

CVE-2024-7149 - Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.8 - Authenticated (Contribu…

The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.8 via multiple style parameters. This makes it possible for authenticated attackers, with Contributor-level access and above, to …

πŸ“… Published: Sept. 27, 2024, 1:52 p.m. πŸ”„ Last Modified: April 8, 2026, 5:01 p.m.

5.3

CVSS3.1

CVE-2024-45863 -

A null-dereference vulnerability involving parsing requests specifying invalid protocols can cause the application to crash or potentially result in other undesirable effects. This issue affects Facebook Thrift from v2024.09.09.00 until v2024.09.23.00.

πŸ“… Published: Sept. 27, 2024, 1:50 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-45773 -

A use-after-free vulnerability involving upgradeToRocket requests can cause the application to crash or potentially result in code execution or other undesirable effects. This issue affects Facebook Thrift prior to v2024.09.09.00.

πŸ“… Published: Sept. 27, 2024, 1:49 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2024-9282 - bg5sbk MiniCMS page-edit.php cross-site request forgery

A vulnerability was found in bg5sbk MiniCMS 1.11. It has been classified as problematic. Affected is an unknown function of the file page-edit.php. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and ma…

πŸ“… Published: Sept. 27, 2024, 1 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 12:18 p.m.
Total resulsts: 349182
Page 8447 of 34,919
Β« previous page Β» next page
Filters