7.5

CVSS3.1

CVE-2024-41708 -

An issue was discovered in AdaCore ada_web_services 20.0 allows an attacker to escalate privileges and steal sessions via the Random_String() function in the src/core/aws-utils.adb module.

πŸ“… Published: Sept. 25, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS3.1

CVE-2024-45750 -

An issue in TheGreenBow Windows Standard VPN Client 6.87.108 (and older), Windows Enterprise VPN Client 6.87.109 (and older), Windows Enterprise VPN Client 7.5.007 (and older), Android VPN Client 6.4.5 (and older) VPN Client Linux 3.4 (and older), VPN Client MacOS 2.4.10 (and older) allows a remote…

πŸ“… Published: Sept. 25, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-22893 -

OpenSlides 4.0.15 verifies passwords by comparing password hashes using a function with content-dependent runtime. This can allow attackers to obtain information about the password hash using a timing attack.

πŸ“… Published: Sept. 25, 2024, midnight πŸ”„ Last Modified: June 13, 2025, 3:03 p.m.

7.5

CVSS3.1

CVE-2024-22892 -

OpenSlides 4.0.15 was discovered to be using a weak hashing algorithm to store passwords.

πŸ“… Published: Sept. 25, 2024, midnight πŸ”„ Last Modified: March 14, 2025, 4:15 p.m.

5.4

CVSS3.1

CVE-2023-51157 -

Cross Site Scripting vulnerability in ZKTeco WDMS v.5.1.3 Pro allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted script to the Emp Name parameter.

πŸ“… Published: Sept. 25, 2024, midnight πŸ”„ Last Modified: Oct. 2, 2024, 4:58 p.m.

4.7

CVSS3.1

CVE-2024-46600 -

dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/doAdminAction.php?act=delCate&id=31

πŸ“… Published: Sept. 25, 2024, midnight πŸ”„ Last Modified: May 27, 2025, 6:59 p.m.

6.3

CVSS3.1

CVE-2024-46485 -

dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=addCate

πŸ“… Published: Sept. 25, 2024, midnight πŸ”„ Last Modified: May 27, 2025, 7:05 p.m.

6.1

CVSS3.1

CVE-2024-46655 -

A reflected cross-site scripting (XSS) vulnerability in Ellevo 6.2.0.38160 allows attackers to execute arbitrary code in the context of a user's browser via a crafted payload or URL.

πŸ“… Published: Sept. 25, 2024, midnight πŸ”„ Last Modified: Oct. 2, 2024, 3:40 p.m.

8

CVSS3.1

CVE-2024-44678 -

Gigastone TR1 Travel Router R101 v1.0.2 is vulnerable to Command Injection. This allows an authenticated attacker to execute arbitrary commands on the device by sending a crafted HTTP request to the ssid parameter in the request.

πŸ“… Published: Sept. 25, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-41445 -

Library MDF (mdflib) v2.1 is vulnerable to a heap-based buffer overread via a crafted mdf4 file is parsed using the ReadData function

πŸ“… Published: Sept. 25, 2024, midnight πŸ”„ Last Modified: March 25, 2025, 5:16 p.m.
Total resulsts: 349182
Page 8482 of 34,919
Β« previous page Β» next page
Filters