4.8

CVSS3.1

CVE-2024-45811 - server.fs.deny bypassed when using ?import&raw in vite

Vite a frontend build tooling framework for javascript. In affected versions the contents of arbitrary files can be returned to the browser. `@fs` denies access to files outside of Vite serving allow list. Adding `?import&raw` to the URL bypasses this limitation and returns the file content if it e…

πŸ“… Published: Sept. 17, 2024, 6:44 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-45537 - Apache Druid: Users can provide MySQL JDBC properties not on allow list

Apache Druid allows users with certain permissions to read data from other database systems using JDBC. This functionality allows trusted users to set up Druid lookups or run ingestion tasks. Druid also allows administrators to configure a list of allowed properties that users are able to provide f…

πŸ“… Published: Sept. 17, 2024, 6:37 p.m. πŸ”„ Last Modified: March 14, 2025, 3:15 p.m.

5.3

CVSS3.1

CVE-2024-45384 - Apache Druid: Padding oracle in druid-pac4j extension that allows an attacker to manipulate a pac4j…

Padding Oracle vulnerability in Apache Druid extension, druid-pac4j. This could allow an attacker to manipulate a pac4j session cookie. This issue affects Apache Druid versions 0.18.0 through 30.0.0. Since the druid-pac4j extension is optional and disabled by default, Druid installations not using…

πŸ“… Published: Sept. 17, 2024, 6:36 p.m. πŸ”„ Last Modified: March 14, 2025, 8:15 p.m.

6.3

CVSS4.0

CVE-2024-8947 - MicroPython objarray.c use after free

A vulnerability was found in MicroPython 1.22.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file py/objarray.c. The manipulation leads to use after free. The attack can be launched remotely. The complexity of an attack is rather high. The exp…

πŸ“… Published: Sept. 17, 2024, 6:31 p.m. πŸ”„ Last Modified: Sept. 24, 2024, 1:17 p.m.

6.9

CVSS4.0

CVE-2024-8946 - MicroPython VFS Unmount vfs.c mp_vfs_umount heap-based overflow

A vulnerability was found in MicroPython 1.23.0. It has been classified as critical. Affected is the function mp_vfs_umount of the file extmod/vfs.c of the component VFS Unmount Handler. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit …

πŸ“… Published: Sept. 17, 2024, 6:31 p.m. πŸ”„ Last Modified: Sept. 24, 2024, 1:11 p.m.

5.3

CVSS3.1

CVE-2024-45612 - Insert tag injection via canonical URL in Contao

Contao is an Open Source CMS. In affected versions an untrusted user can inject insert tags into the canonical tag, which are then replaced on the web page (front end). Users are advised to update to Contao 4.13.49, 5.3.15 or 5.4.3. Users unable to upgrade should disable canonical tags in the root …

πŸ“… Published: Sept. 17, 2024, 6:29 p.m. πŸ”„ Last Modified: Sept. 23, 2024, 7:33 p.m.

5.1

CVSS4.0

CVE-2024-45803 - Cross site scripting (XSS) Vulnerability on route /wireui/button?label=Content in wireui

Wire UI is a library of components and resources to empower Laravel and Livewire application development. A potential Cross-Site Scripting (XSS) vulnerability has been identified in the `/wireui/button` endpoint, specifically through the `label` query parameter. Malicious actors could exploit this …

πŸ“… Published: Sept. 17, 2024, 6:22 p.m. πŸ”„ Last Modified: Oct. 7, 2024, 5:05 p.m.

8.1

CVSS3.1

CVE-2024-43460 - Dynamics 365 Business Central Elevation of Privilege Vulnerability

Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacker to elevate privileges over a network.

πŸ“… Published: Sept. 17, 2024, 6:15 p.m. πŸ”„ Last Modified: Dec. 31, 2024, 11:03 p.m.

9.8

CVSS3.1

CVE-2024-38183 - GroupMe Elevation of Privilege Vulnerability

An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network.

πŸ“… Published: Sept. 17, 2024, 6:15 p.m. πŸ”„ Last Modified: Dec. 31, 2024, 11:15 p.m.

7.5

CVSS3.1

CVE-2024-8900 - firefox: Clipboard write permission bypass

An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events. This vulnerability affects Firefox < 129, Firefox ESR < 128.3, and Thunderbird < 128.3.

πŸ“… Published: Sept. 17, 2024, 6:14 p.m. πŸ”„ Last Modified: March 18, 2025, 9:15 p.m.
Total resulsts: 349182
Page 8540 of 34,919
Β« previous page Β» next page
Filters