7.5

CVSS3.1

CVE-2024-8287 -

Anbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the Anbox Stream Agent. An attacker must be able to machine-in-the-middle the Anbox Stream Agent from within an internal network before they can attempt to take advantage of this.

๐Ÿ“… Published: Sept. 18, 2024, 6:35 p.m. ๐Ÿ”„ Last Modified: Sept. 24, 2024, 3:52 p.m.

7.5

CVSS3.1

CVE-2024-45601 - Local file Inclusion via static file serving functionality in Mesop

Mesop is a Python-based UI framework designed for rapid web apps development. A vulnerability has been discovered and fixed in Mesop that could potentially allow unauthorized access to files on the server hosting the Mesop application. The vulnerability was related to insufficient input validation โ€ฆ

๐Ÿ“… Published: Sept. 18, 2024, 5:49 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.7

CVSS3.1

CVE-2024-46989 - Multiple caveats on resources of the same type can result in no permission when permission is expecโ€ฆ

spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for customer applications. Multiple caveats over the same indirect subject type on the same relation can result in no permission being returned when permission is expected. If the resource โ€ฆ

๐Ÿ“… Published: Sept. 18, 2024, 5:29 p.m. ๐Ÿ”„ Last Modified: Sept. 4, 2025, 4:41 p.m.

6.5

CVSS3.1

CVE-2024-46978 - Missing checks for notification filter preferences editions in XWiki Platform

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible for any user knowing the ID of a notification filter preference of another user, to enable/disable it or even delete it. The impact is that the target user might start loosing notiโ€ฆ

๐Ÿ“… Published: Sept. 18, 2024, 5:25 p.m. ๐Ÿ”„ Last Modified: Feb. 7, 2025, 3:48 p.m.

5.3

CVSS3.1

CVE-2024-46979 - Data leak of notification filters of users in XWiki Platform

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to get access to notification filters of any user by using a URL such as `<hostname>xwiki/bin/get/XWiki/Notifications/Code/NotificationFilterPreferenceLivetableResults?outputSyntaxโ€ฆ

๐Ÿ“… Published: Sept. 18, 2024, 5:23 p.m. ๐Ÿ”„ Last Modified: Feb. 7, 2025, 3:39 p.m.

7.7

CVSS3.1

CVE-2024-46987 - Arbitrary path traversal in Camaleon CMS

Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. A path traversal vulnerability accessible via MediaController's download_private_file method allows authenticated users to download any file on the web server Camaleon CMS is running on (depending on the file pโ€ฆ

๐Ÿ“… Published: Sept. 18, 2024, 5:15 p.m. ๐Ÿ”„ Last Modified: April 17, 2025, 7:15 p.m.

10

CVSS3.1

CVE-2024-46986 - Arbitrary file write leading to RCE in Camaleon CMS

Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. An arbitrary file write vulnerability accessible via the upload method of the MediaController allows authenticated users to write arbitrary files to any location on the web server Camaleon CMS is running on (deโ€ฆ

๐Ÿ“… Published: Sept. 18, 2024, 5:14 p.m. ๐Ÿ”„ Last Modified: April 17, 2025, 6:15 p.m.

4.3

CVSS3.1

CVE-2024-45298 - Disabled user can bypass lockout by requesting password reset in wiki.js

Wiki.js is an open source wiki app built on Node.js. A disabled user can still gain access to a wiki by abusing the password reset function. While setting up SMTP e-mail's on my server, I tested said e-mails by performing a password reset with my test user. To my shock, not only did it let me resetโ€ฆ

๐Ÿ“… Published: Sept. 18, 2024, 5:05 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5

CVSS3.1

CVE-2024-46990 - SSRF Loopback IP filter bypass in directus

Directus is a real-time API and App dashboard for managing SQL database content. When relying on blocking access to localhost using the default `0.0.0.0` filter a user may bypass this block by using other registered loopback devices (like `127.0.0.2` - `127.127.127.127`). This issue has been addresโ€ฆ

๐Ÿ“… Published: Sept. 18, 2024, 4:55 p.m. ๐Ÿ”„ Last Modified: Nov. 17, 2025, 6:49 p.m.

5.3

CVSS3.1

CVE-2024-45813 - ReDoS vulnerability in multiparametric routes in find-my-way

find-my-way is a fast, open source HTTP router, internally using a Radix Tree (aka compact Prefix Tree), supports route params, wildcards, and it's framework independent. A bad regular expression is generated any time one has two parameters within a single segment, when adding a `-` at the end, likโ€ฆ

๐Ÿ“… Published: Sept. 18, 2024, 4:47 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 8511 of 34,919
ยซ previous page ยป next page
Filters