6.8

CVSS4.0

CVE-2024-6785 - MXview One and MXview One Central Manager Series store cleartext credentials in a local file

The configuration file stores credentials in cleartext. An attacker with local access rights can read or modify the configuration file, potentially resulting in the service being abused due to sensitive information exposure.

πŸ“… Published: Sept. 21, 2024, 4:07 a.m. πŸ”„ Last Modified: Sept. 27, 2024, 6:59 p.m.

8.8

CVSS3.1

CVE-2024-47210 -

Gladys Assistant before 4.45.1 allows Privilege Escalation (a user changing their own role) because req.body.role can be used in updateMySelf in server/api/controllers/user.controller.js.

πŸ“… Published: Sept. 21, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-47219 -

An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows shell command injection.

πŸ“… Published: Sept. 21, 2024, midnight πŸ”„ Last Modified: April 28, 2025, 5:19 p.m.

0.0

CVE-2024-9063 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-2143 Reason: This candidate is a reservation duplicate of CVE-2023-2143. Notes: All CVE users should reference CVE-2023-2143 instead of this candidate. All references and descriptions in this candidate have been removed to prevent…

πŸ“… Published: Sept. 20, 2024, 9:55 p.m. πŸ”„ Last Modified: Sept. 25, 2024, 1:15 a.m.

4.8

CVSS3.1

CVE-2024-45793 - Cross-site Scripting from in Confidant API call

Confidant is a open source secret management service that provides user-friendly storage and access to secrets. The following endpoints are subject to a cross site scripting vulnerability: GET /v1/credentials, GET /v1/credentials/, GET /v1/archive/credentials/, GET /v1/archive/credentials, POST /v1…

πŸ“… Published: Sept. 20, 2024, 7:07 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.3

CVSS3.1

CVE-2024-47061 - Arbitrary DOM attributes in element.attributes and leaf.attributes in Platejs

Plate is a javascript toolkit that makes it easier for you to develop with Slate, a popular framework for building text editors. One longstanding feature of Plate is the ability to add custom DOM attributes to any element or leaf using the `attributes` property. These attributes are passed to the n…

πŸ“… Published: Sept. 20, 2024, 7:04 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.4

CVSS4.0

CVE-2024-47062 - Multiple SQL Injections and ORM Leak in navidrome

Navidrome is an open source web-based music collection server and streamer. Navidrome automatically adds parameters in the URL to SQL queries. This can be exploited to access information by adding parameters like `password=...` in the URL (ORM Leak). Furthermore, the names of the parameters are not…

πŸ“… Published: Sept. 20, 2024, 7:01 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 5:45 p.m.

6.5

CVSS3.1

CVE-2024-42351 - Possible Data Tampering & Loss of Public Datasets in Galaxy

Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. An attacker can potentially replace the contents of public datasets resulting in data loss or tampering. All supported branches of Galaxy (and m…

πŸ“… Published: Sept. 20, 2024, 6:56 p.m. πŸ”„ Last Modified: Aug. 15, 2025, 2:17 p.m.

7.6

CVSS3.1

CVE-2024-42346 - Stored Cross Site Scripting (Stored XSS) in Galaxy

Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. The editor visualization, /visualizations endpoint, can be used to store HTML tags and trigger javascript execution upon edit operation. All sup…

πŸ“… Published: Sept. 20, 2024, 6:53 p.m. πŸ”„ Last Modified: Aug. 15, 2025, 2:19 p.m.

6.6

CVSS3.0

CVE-2024-45229 -

The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen, banner display, and device registration, do not require authentication. However, it was discovered that for Directors directly connected to the Internet, one of these APIs can be…

πŸ“… Published: Sept. 20, 2024, 6:09 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 8500 of 34,919
Β« previous page Β» next page
Filters