6.5

CVSS3.1

CVE-2024-46644 -

eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via edit_file.

πŸ“… Published: Sept. 20, 2024, midnight πŸ”„ Last Modified: April 16, 2025, 7:28 p.m.

6.1

CVSS3.1

CVE-2024-42697 -

Cross Site Scripting vulnerability in Leotheme Leo Product Search Module v.2.1.6 and earlier allows a remote attacker to execute arbitrary code via the q parameter of the product search function.

πŸ“… Published: Sept. 20, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-45806 - Potential manipulate `x-envoy` headers from external sources in envoy

Envoy is a cloud-native high-performance edge/middle/service proxy. A security vulnerability in Envoy allows external clients to manipulate Envoy headers, potentially leading to unauthorized access or other malicious actions within the mesh. This issue arises due to Envoy's default configuration of…

πŸ“… Published: Sept. 19, 2024, 11:34 p.m. πŸ”„ Last Modified: Oct. 15, 2024, 4:03 p.m.

7.5

CVSS3.1

CVE-2024-45807 - oghttp2 crash on OnBeginHeadersForStream in envoy

Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy's 1.31 is using `oghttp` as the default HTTP/2 codec, and there are potential bugs around stream management in the codec. To resolve this Envoy will switch off the `oghttp2` by default. The impact of this issue is that envoy …

πŸ“… Published: Sept. 19, 2024, 11:34 p.m. πŸ”„ Last Modified: Sept. 25, 2024, 5:12 p.m.

6.5

CVSS3.1

CVE-2024-45808 - Malicious log injection via access logs in envoy

Envoy is a cloud-native high-performance edge/middle/service proxy. A vulnerability has been identified in Envoy that allows malicious attackers to inject unexpected content into access logs. This is achieved by exploiting the lack of validation for the `REQUESTED_SERVER_NAME` field for access logg…

πŸ“… Published: Sept. 19, 2024, 11:34 p.m. πŸ”„ Last Modified: Sept. 25, 2024, 5:18 p.m.

5.3

CVSS3.1

CVE-2024-45809 - Jwt filter crash in the clear route cache with remote JWKs in envoy

Envoy is a cloud-native high-performance edge/middle/service proxy. Jwt filter will lead to an Envoy crash when clear route cache with remote JWKs. In the following case: 1. remote JWKs are used, which requires async header processing; 2. clear_route_cache is enabled on the provider; 3. header oper…

πŸ“… Published: Sept. 19, 2024, 11:34 p.m. πŸ”„ Last Modified: Sept. 24, 2024, 8:12 p.m.

6.5

CVSS3.1

CVE-2024-45810 - Envoy crashes for LocalReply in http async client

Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy will crash when the http async client is handling `sendLocalReply` under some circumstance, e.g., websocket upgrade, and requests mirroring. The http async client will crash during the `sendLocalReply()` in http async client,…

πŸ“… Published: Sept. 19, 2024, 11:34 p.m. πŸ”„ Last Modified: Jan. 30, 2026, 7:56 p.m.

5.3

CVSS4.0

CVE-2024-9009 - code-projects Online Quiz Site showtest.php sql injection

A vulnerability, which was classified as critical, has been found in code-projects Online Quiz Site 1.0. This issue affects some unknown processing of the file showtest.php. The manipulation of the argument subid leads to sql injection. The attack may be initiated remotely. The exploit has been dis…

πŸ“… Published: Sept. 19, 2024, 11:31 p.m. πŸ”„ Last Modified: Oct. 23, 2025, 8:06 p.m.

7.3

CVSS3.1

CVE-2024-46999 - User Grant Deactivation not Working in Zitadel

Zitadel is an open source identity management platform. ZITADEL's user grants deactivation mechanism did not work correctly. Deactivated user grants were still provided in token, which could lead to unauthorized access to applications and resources. Additionally, the management and auth API always …

πŸ“… Published: Sept. 19, 2024, 11:11 p.m. πŸ”„ Last Modified: Sept. 24, 2024, 8:20 p.m.

8.1

CVSS3.1

CVE-2024-47000 - Service Users Deactivation not Working in Zitadel

Zitadel is an open source identity management platform. ZITADEL's user account deactivation mechanism did not work correctly with service accounts. Deactivated service accounts retained the ability to request tokens, which could lead to unauthorized access to applications and resources. Versions 2.…

πŸ“… Published: Sept. 19, 2024, 11:10 p.m. πŸ”„ Last Modified: Sept. 24, 2024, 8:25 p.m.
Total resulsts: 349182
Page 8504 of 34,919
Β« previous page Β» next page
Filters