9.8
CVE-2024-8503 - VICIdial Unauthenticated SQL Injection
An unauthenticated attacker can leverage a time-based SQL injection vulnerability in VICIdial to enumerate database records. By default, VICIdial stores plaintext credentials within the database.
10
CVE-2024-45409 - The Ruby SAML library vulnerable to a SAML authentication bypass via Incorrect XPath selector
The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify the signature of the SAML Response. An unauthenticated attacker with access to any signed saml document (by the IdP) can thus forge a SAML Response/Aโฆ
7.4
CVE-2024-45596 - Directus's session is cached for OpenID and OAuth2 if `redirect` is not used
Directus is a real-time API and App dashboard for managing SQL database content. An unauthenticated user can access credentials of last authenticated user via OpenID or OAuth2 where the authentication URL did not include redirect query string. This happens because on that endpoint for both OpenId aโฆ
8.8
CVE-2024-37980 - Microsoft SQL Server Elevation of Privilege Vulnerability
Microsoft SQL Server Elevation of Privilege Vulnerability
8.4
CVE-2024-38194 - Azure Web Apps Elevation of Privilege Vulnerability
An authenticated attacker can exploit an improper authorization vulnerability in Azure Web Apps to elevate privileges over a network.
7.3
CVE-2024-43495 - Windows libarchive Remote Code Execution Vulnerability
Windows libarchive Remote Code Execution Vulnerability
9.8
CVE-2024-43491 - Microsoft Windows Update Remote Code Execution Vulnerability
Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, version 1507 (initial version released July 2015). This means that an attacker could exploit these previously mitigated vulnerabilities on Wiโฆ
6.5
CVE-2024-43487 - Windows Mark of the Web Security Feature Bypass Vulnerability
Windows Mark of the Web Security Feature Bypass Vulnerability
7.8
CVE-2024-30073 - Windows Security Zone Mapping Security Feature Bypass Vulnerability
Windows Security Zone Mapping Security Feature Bypass Vulnerability
8.5
CVE-2024-43479 - Microsoft Power Automate Desktop Remote Code Execution Vulnerability
Microsoft Power Automate Desktop Remote Code Execution Vulnerability