7.5

CVSS3.1

CVE-2024-47220 - WEBrick: HTTP request smuggling

An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., "GET /admin HTTP/1.1\r\n" inside of a "POST /user HTTP/1.1\r\n" request. NOTE: the supplier's position is "Webrick …

πŸ“… Published: Sept. 22, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-47221 -

CheckUser in ScadaServerEngine/MainLogic.cs in Rapid SCADA through 5.8.4 allows an empty password.

πŸ“… Published: Sept. 22, 2024, midnight πŸ”„ Last Modified: March 19, 2025, 4:15 p.m.

9.8

CVSS3.1

CVE-2024-47218 -

An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows bypassing authentication.

πŸ“… Published: Sept. 22, 2024, midnight πŸ”„ Last Modified: April 28, 2025, 5:22 p.m.

5.4

CVSS3.1

CVE-2024-47226 -

A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. An authenticated user can inject arbitrary JavaScript or HTML into the "Top banner" field. NOTE: Multiple third parties …

πŸ“… Published: Sept. 22, 2024, midnight πŸ”„ Last Modified: June 30, 2025, 2:50 p.m.

2.3

CVSS4.0

CVE-2024-9075 - Stirling-Tools Stirling-PDF Markdown-to-PDF cross site scripting

A vulnerability was found in Stirling-Tools Stirling-PDF up to 0.28.3. It has been declared as problematic. This vulnerability affects unknown code of the component Markdown-to-PDF. The manipulation leads to cross site scripting. The attack can be initiated remotely. The complexity of an attack is …

πŸ“… Published: Sept. 21, 2024, 11 p.m. πŸ”„ Last Modified: Sept. 30, 2024, 3:27 p.m.

8.8

CVSS3.1

CVE-2024-42323 - Apache HertzBeat: RCE by snakeYaml deser load malicious xml

SnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating).Β  This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat (incubating): before 1.6.0. Users are recommended to upgrade to version 1.6.0, which fixes the issue.

πŸ“… Published: Sept. 21, 2024, 9:30 a.m. πŸ”„ Last Modified: July 1, 2025, 8:27 p.m.

4.4

CVSS3.1

CVE-2024-8680 - MailChimp for Wordpress <= 4.9.16 - Authenticated (Administrator+) Stored Cross-Site Scripting

The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.9.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-lev…

πŸ“… Published: Sept. 21, 2024, 8:35 a.m. πŸ”„ Last Modified: April 8, 2026, 5:14 p.m.

6.3

CVSS4.0

CVE-2024-9048 - y_project RuoYi Backend User Import SysUserServiceImpl.java SysUserServiceImpl cross site scripting

A vulnerability was found in y_project RuoYi up to 4.7.9. It has been declared as problematic. Affected by this vulnerability is the function SysUserServiceImpl of the file ruoyi-system/src/main/java/com/ruoyi/system/service/impl/SysUserServiceImpl.java of the component Backend User Import. The man…

πŸ“… Published: Sept. 21, 2024, 8:31 a.m. πŸ”„ Last Modified: Sept. 30, 2024, 1 p.m.

6

CVSS4.0

CVE-2024-6787 - MXview One Series vulnerable to Time-of-check Time-of-use (TOCTOU) Race Condition

This vulnerability occurs when an attacker exploits a race condition between the time a file is checked and the time it is used (TOCTOU). By exploiting this race condition, an attacker can write arbitrary files to the system. This could allow the attacker to execute malicious code and potentially c…

πŸ“… Published: Sept. 21, 2024, 4:20 a.m. πŸ”„ Last Modified: Sept. 30, 2024, 6:02 p.m.

6

CVSS4.0

CVE-2024-6786 - MXview One Series vulnerable to Path Traversal

The vulnerability allows an attacker to craft MQTT messages that include relative path traversal sequences, enabling them to read arbitrary files on the system. This could lead to the disclosure of sensitive information, such as configuration files and JWT signing secrets.

πŸ“… Published: Sept. 21, 2024, 4:14 a.m. πŸ”„ Last Modified: Sept. 30, 2024, 6:31 p.m.
Total resulsts: 349182
Page 8499 of 34,919
Β« previous page Β» next page
Filters