4.9

CVSS3.1

CVE-2024-43188 - IBM Business Automation Workflow improper input validation

IBM Business Automation Workflow 22.0.2, 23.0.1, 23.0.2, and 24.0.0 could allow a privileged user to perform unauthorized activities due to improper client side validation.

πŸ“… Published: Sept. 18, 2024, 11:39 a.m. πŸ”„ Last Modified: Sept. 29, 2024, 12:24 a.m.

10

CVSS3.1

CVE-2024-8887 - Authentication bypass vulnerability on CIRCUTOR Q-SMT

CIRCUTOR Q-SMT in its firmware version 1.0.4, could be affected by a denial of service (DoS) attack if an attacker with access to the web service bypasses the authentication mechanisms on the login page, allowing the attacker to use all the functionalities implemented at web level that allow intera…

πŸ“… Published: Sept. 18, 2024, 11:05 a.m. πŸ”„ Last Modified: Oct. 1, 2024, 5:30 p.m.

6.5

CVSS3.1

CVE-2024-8969 - The SYSCOM Group OMFLOW - Exposure of Sensitive Data

OMFLOW from The SYSCOM Group has a vulnerability involving the exposure of sensitive data. This allows remote attackers who have logged into the system to obtain password hashes of all users and administrators.

πŸ“… Published: Sept. 18, 2024, 6:53 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-43778 -

OS command injection vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings.

πŸ“… Published: Sept. 18, 2024, 6:14 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-47001 -

Hidden functionality issue in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings.

πŸ“… Published: Sept. 18, 2024, 6:08 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-41929 -

Improper authentication vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings.

πŸ“… Published: Sept. 18, 2024, 6:07 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-6641 - WP Hardening – Fix Your WordPress Security <= 1.2.6 - Unauthenticated Security Feature Bypass to Us…

The WP Hardening – Fix Your WordPress Security plugin for WordPress is vulnerable to Security Feature Bypass in all versions up to, and including, 1.2.6. This is due to use of an incorrect regular expression within the "Stop User Enumeration" feature. This makes it possible for unauthenticated atta…

πŸ“… Published: Sept. 18, 2024, 5:31 a.m. πŸ”„ Last Modified: April 8, 2026, 5:02 p.m.

6.1

CVSS3.1

CVE-2024-45366 -

Welcart e-Commerce prior to 2.11.2 contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the user's web browser.

πŸ“… Published: Sept. 18, 2024, 5:20 a.m. πŸ”„ Last Modified: July 10, 2025, 1:21 p.m.

8.8

CVSS3.1

CVE-2024-42404 -

SQL injection vulnerability in Welcart e-Commerce prior to 2.11.2 allows an attacker who can login to the product to obtain or alter the information stored in the database.

πŸ“… Published: Sept. 18, 2024, 5:20 a.m. πŸ”„ Last Modified: July 10, 2025, 1:22 p.m.

8.4

CVSS3.1

CVE-2024-45679 -

Heap-based buffer overflow vulnerability in Assimp versions prior to 5.4.3 allows a local attacker to execute arbitrary code by importing a specially crafted file into the product.

πŸ“… Published: Sept. 18, 2024, 3:35 a.m. πŸ”„ Last Modified: June 13, 2025, 7:03 p.m.
Total resulsts: 349182
Page 8518 of 34,919
Β« previous page Β» next page
Filters