6.1

CVSS3.1

CVE-2024-8883 - Keycloak: vulnerable redirect uri validation results in open redirec

A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as authorization codes to be exposed to the attacker, potentially leadi…

📅 Published: Sept. 19, 2024, 3:13 p.m. 🔄 Last Modified: April 1, 2026, 1:27 p.m.

7.7

CVSS3.1

CVE-2024-8698 - Keycloak-saml-core: improper verification of saml responses leading to privilege escalation in keyc…

A flaw exists in the SAML signature validation method within the Keycloak XMLSignatureUtil class. The method incorrectly determines whether a SAML signature is for the full document or only for specific assertions based on the position of the signature in the XML document, rather than the Reference…

📅 Published: Sept. 19, 2024, 3:12 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.4

CVSS3.1

CVE-2024-7207 - envoy: Server-side request forgery via HTTP header manipulation

Duplicate of CVE-2024-45806.

📅 Published: Sept. 19, 2024, 3 p.m. 🔄 Last Modified: Sept. 30, 2024, 7:15 p.m.

9.8

CVSS3.1

CVE-2024-45410 - HTTP client can remove the X-Forwarded headers in Traefik

Traefik is a golang, Cloud Native Application Proxy. When a HTTP request is processed by Traefik, certain HTTP headers such as X-Forwarded-Host or X-Forwarded-Port are added by Traefik before the request is routed to the application. For a HTTP client, it should not be possible to remove or modify …

📅 Published: Sept. 19, 2024, 2:48 p.m. 🔄 Last Modified: Sept. 25, 2024, 5:39 p.m.

9.3

CVSS4.0

CVE-2024-7785 - Reflected XSS in Ece Software's Electronic Ticket System

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ece Software Electronic Ticket System allows Reflected XSS, Cross-Site Scripting (XSS).This issue affects Electronic Ticket System: before 2024.08.

📅 Published: Sept. 19, 2024, 1:30 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS4.0

CVE-2024-8986 - Information Leakage in grafana-plugin-sdk-go

The grafana plugin SDK bundles build metadata into the binaries it compiles; this metadata includes the repository URI for the plugin being built, as retrieved by running `git remote get-url origin`. If credentials are included in the repository URI (for instance, to allow for fetching of private…

📅 Published: Sept. 19, 2024, 10:57 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2024-47089 - Unauthorized Transaction Manipulation Vulnerability

This vulnerability exists in the Apex Softcell LD Geo due to improper validation of the transaction token ID in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating the transaction token ID in the API request leading to unauthorized access and modifica…

📅 Published: Sept. 19, 2024, 6:18 a.m. 🔄 Last Modified: Sept. 26, 2024, 7:09 p.m.

9.3

CVSS4.0

CVE-2024-47088 - User Enumeration vulnerability

This vulnerability exists in Apex Softcell LD Geo due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack on login OTP, which could lead to gain unauthorized access to othe…

📅 Published: Sept. 19, 2024, 6:13 a.m. 🔄 Last Modified: Sept. 26, 2024, 7:12 p.m.

8.7

CVSS4.0

CVE-2024-47087 - Information Disclosure Vulnerability

This vulnerability exists in Apex Softcell LD Geo due to improper validation of the certain parameters (Client ID, DPID or BOID) in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating parameters in the API request body leading to exposure of sensitive…

📅 Published: Sept. 19, 2024, 6:08 a.m. 🔄 Last Modified: Sept. 26, 2024, 3:25 p.m.

8.7

CVSS4.0

CVE-2024-47086 - OTP Bypass Vulnerability

This vulnerability exists in Apex Softcell LD DP Back Office due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by providing arbitrary OTP value for authentication and subsequently changing its API r…

📅 Published: Sept. 19, 2024, 6:03 a.m. 🔄 Last Modified: Sept. 26, 2024, 3:29 p.m.
Total resulsts: 349182
Page 8508 of 34,919
« previous page » next page
Filters