7.5

CVSS3.1

CVE-2024-8941 - Path Traversal vulnerability on Scriptcase

Path traversal vulnerability in Scriptcase version 9.4.019, in /scriptcase/devel/compat/nm_edit_php_edit.php (in the “subpage” parameter), which allows unauthenticated remote users to bypass SecurityManager's intended restrictions and list and/or read a parent directory via a “/...” or directly int…

📅 Published: Sept. 24, 2024, 11:50 a.m. 🔄 Last Modified: Sept. 30, 2024, 7:45 p.m.

10

CVSS3.1

CVE-2024-8940 - Unrestricted Upload of File with Dangerous Type vulnerability on Scriptcase

Vulnerability in the Scriptcase application version 9.4.019, which involves the arbitrary upload of a file via /scriptcase/devel/lib/third/jquery_plugin/jQuery-File-Upload/server/php/ via a POST request. An attacker could upload malicious files to the server due to the application not properly veri…

📅 Published: Sept. 24, 2024, 11:48 a.m. 🔄 Last Modified: Oct. 1, 2024, 5:21 p.m.

4.3

CVSS3.1

CVE-2024-8801 - Happy Addons for Elementor <= 3.12.2 - Authenticated (Contributor+) Sensitive Information Exposure

The Happy Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.2 via the Content Switcher widget. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data in…

📅 Published: Sept. 24, 2024, 11 a.m. 🔄 Last Modified: April 8, 2026, 5:11 p.m.

5.4

CVSS3.1

CVE-2024-9141 - Cross-Site Scripting (XSS) vulnerability in Oct8ne

Cross-Site Scripting (XSS) vulnerability in the Oct8ne system. This flaw could allow an attacker to embed harmful JavaScript code into the body of a chat message. This manipulation occurs when the chat content is intercepted and altered, leading to the execution of the JavaScript payload.

📅 Published: Sept. 24, 2024, 10:50 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS3.1

CVE-2024-38324 - IBM Storage Defender improper certificate validation

IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI does not validate server name during registration and unregistration operations which could expose sensitive information to an attacker with access to the system.

📅 Published: Sept. 24, 2024, 10:24 a.m. 🔄 Last Modified: Sept. 30, 2024, 2:10 p.m.

8

CVSS3.1

CVE-2021-38963 - IBM Aspera Console CSV injection

IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a CSV injection vulnerability. By persuading a victim to open a specially crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the…

📅 Published: Sept. 24, 2024, 10:15 a.m. 🔄 Last Modified: Sept. 30, 2024, 3:48 p.m.

3.7

CVSS3.1

CVE-2022-43845 - IBM Aspera Console information disclosure

IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie.

📅 Published: Sept. 24, 2024, 10:11 a.m. 🔄 Last Modified: Sept. 30, 2024, 3:53 p.m.

9.4

CVSS4.0

CVE-2024-9142 - Local File Inclusion (LFI) in Olgu Computer Systems' e-Belediye

External Control of File Name or Path, : Incorrect Permission Assignment for Critical Resource vulnerability in Olgu Computer Systems e-Belediye allows Manipulating Web Input to File System Calls.This issue affects e-Belediye: before 2.0.642.

📅 Published: Sept. 24, 2024, 8:47 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.9

CVSS3.1

CVE-2024-8436 - WP Easy Gallery – WordPress Gallery Plugin <= 4.8.5 - Authenticated (Subscriber+) SQL Injection

The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to SQL Injection via the 'edit_imageId' and 'edit_imageDelete' parameters in all versions up to, and including, 4.8.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on t…

📅 Published: Sept. 24, 2024, 7:30 a.m. 🔄 Last Modified: April 8, 2026, 5:26 p.m.

4.3

CVSS3.1

CVE-2024-8437 - WP Easy Gallery – WordPress Gallery Plugin <= 4.8.5 - Missing Authorization to Authenticated (Subsc…

The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions hooked via AJAX like wpeg_settings and wpeg_add_gallery in all versions up to, and including, 4.8.5. This makes it possible for authenticat…

📅 Published: Sept. 24, 2024, 7:30 a.m. 🔄 Last Modified: April 8, 2026, 5:21 p.m.
Total resulsts: 349182
Page 8486 of 34,919
« previous page » next page
Filters