4.3

CVSS3.1

CVE-2024-47060 - Unauthorized Access After Organization or Project Deactivation in Zitadel

Zitadel is an open source identity management platform. In Zitadel, even after an organization is deactivated, associated projects, respectively their applications remain active. Users across other organizations can still log in and access through these applications, leading to unauthorized access.โ€ฆ

๐Ÿ“… Published: Sept. 19, 2024, 11:08 p.m. ๐Ÿ”„ Last Modified: Sept. 25, 2024, 4:43 p.m.

5.3

CVSS4.0

CVE-2024-9008 - SourceCodester Best Online News Portal Comment Section news-details.php sql injection

A vulnerability classified as critical was found in SourceCodester Best Online News Portal 1.0. This vulnerability affects unknown code of the file /news-details.php of the component Comment Section. The manipulation of the argument name leads to sql injection. The attack can be initiated remotely.โ€ฆ

๐Ÿ“… Published: Sept. 19, 2024, 11 p.m. ๐Ÿ”„ Last Modified: March 7, 2025, 2:49 p.m.

9.8

CVSS3.1

CVE-2023-27584 - Dragonfly2 vulnerable to hard coded cyptographic key

Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) as an Incubating Level Project. Dragonfly uses JWT to verify user. However, the secret key for JWT, "Secret Key", is hard coded, which leads to authentโ€ฆ

๐Ÿ“… Published: Sept. 19, 2024, 10:54 p.m. ๐Ÿ”„ Last Modified: Dec. 20, 2024, 7:11 p.m.

9.8

CVSS3.1

CVE-2024-46983 - Remote Command Execution(RCE) Vulnerbility in sofa-hessian

sofa-hessian is an internal improved version of Hessian3/4 powered by Ant Group CO., Ltd. The SOFA Hessian protocol uses a blacklist mechanism to restrict deserialization of potentially dangerous classes for security protection. But there is a gadget chain that can bypass the SOFA Hessian blacklistโ€ฆ

๐Ÿ“… Published: Sept. 19, 2024, 10:47 p.m. ๐Ÿ”„ Last Modified: Sept. 25, 2024, 5:46 p.m.

5.4

CVSS3.1

CVE-2024-45614 - Header normalization allows for client to clobber proxy set headers in Puma

Puma is a Ruby/Rack web server built for parallelism. In affected versions clients could clobber values set by intermediate proxies (such as X-Forwarded-For) by providing a underscore version of the same header (X-Forwarded_For). Any users relying on proxy set variables is affected. v6.4.3/v5.6.9 nโ€ฆ

๐Ÿ“… Published: Sept. 19, 2024, 10:42 p.m. ๐Ÿ”„ Last Modified: Nov. 3, 2025, 11:15 p.m.

8.6

CVSS3.1

CVE-2024-46984 - XML External Entity Reference (XXE) vulnerability can lead to a Server Side Request Forgery attack โ€ฆ

The reference validator is a tool to perform advanced validation of FHIR resources for TI applications and interoperability standards. The profile location routine in the referencevalidator commons package is vulnerable to `XML External Entities` attack due to insecure defaults of the used Woodstoxโ€ฆ

๐Ÿ“… Published: Sept. 19, 2024, 10:38 p.m. ๐Ÿ”„ Last Modified: Sept. 25, 2024, 5:49 p.m.

5.3

CVSS4.0

CVE-2024-9007 - jeanmarc77 123solar detailed.php cross site scripting

A vulnerability classified as problematic has been found in jeanmarc77 123solar 1.8.4.5. This affects an unknown part of the file /detailed.php. The manipulation of the argument date1 leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to thโ€ฆ

๐Ÿ“… Published: Sept. 19, 2024, 10:31 p.m. ๐Ÿ”„ Last Modified: Sept. 25, 2024, 6:40 p.m.

5.3

CVSS4.0

CVE-2024-9006 - jeanmarc77 123solar config_invt1.php code injection

A vulnerability was found in jeanmarc77 123solar 1.8.4.5. It has been rated as critical. Affected by this issue is some unknown functionality of the file config/config_invt1.php. The manipulation of the argument PASSOx leads to code injection. The attack may be launched remotely. The exploit has beโ€ฆ

๐Ÿ“… Published: Sept. 19, 2024, 10:31 p.m. ๐Ÿ”„ Last Modified: Sept. 25, 2024, 6:44 p.m.

5.3

CVSS4.0

CVE-2024-9004 - D-Link DAR-7000 Backup_Server_commit.php os command injection

A vulnerability classified as critical has been found in D-Link DAR-7000 up to 20240912. Affected is an unknown function of the file /view/DBManage/Backup_Server_commit.php. The manipulation of the argument host leads to os command injection. It is possible to launch the attack remotely. The exploiโ€ฆ

๐Ÿ“… Published: Sept. 19, 2024, 9 p.m. ๐Ÿ”„ Last Modified: Sept. 23, 2024, 5:29 p.m.

5.3

CVSS4.0

CVE-2024-9003 - Jinan Chicheng Company JFlow Attachment EntityMutliFile_Load.do AttachmentUploadController access cโ€ฆ

A vulnerability was found in Jinan Chicheng Company JFlow 2.0.0. It has been rated as problematic. This issue affects the function AttachmentUploadController of the file /WF/Ath/EntityMutliFile_Load.do of the component Attachment Handler. The manipulation of the argument oid leads to improper accesโ€ฆ

๐Ÿ“… Published: Sept. 19, 2024, 9 p.m. ๐Ÿ”„ Last Modified: Sept. 25, 2024, 5:18 p.m.
Total resulsts: 349182
Page 8505 of 34,919
ยซ previous page ยป next page
Filters