5.3

CVSS4.0

CVE-2024-8610 - SourceCodester Best House Rental Management System New Tenant Page index.php cross site scripting

A vulnerability classified as problematic has been found in SourceCodester Best House Rental Management System 1.0. Affected is an unknown function of the file /index.php?page=tenants of the component New Tenant Page. The manipulation of the argument Last Name/First Name/Middle Name leads to cross …

πŸ“… Published: Sept. 9, 2024, 8:31 p.m. πŸ”„ Last Modified: Sept. 17, 2024, 6:48 p.m.

8.2

CVSS3.1

CVE-2024-6796 - Vulnerability in Baxter Connex Health Portal

In Baxter Connex health portal released before 8/30/2024, an improper access control vulnerability has been found that could allow an unauthenticated attacker to gain unauthorized access to Connex portal's database and/or modify content.

πŸ“… Published: Sept. 9, 2024, 7:28 p.m. πŸ”„ Last Modified: Sept. 20, 2024, 2:53 p.m.

10

CVSS3.1

CVE-2024-6795 - Vulnerability in Baxter Connex Health Portal

In Connex health portal released before8/30/2024, SQL injection vulnerabilities were found that could have allowed an unauthenticated attacker to gain unauthorized access to Connex portal's database.Β  An attacker could have submitted a crafted payload to Connex portal that could have resulted in m…

πŸ“… Published: Sept. 9, 2024, 7:24 p.m. πŸ”„ Last Modified: Sept. 20, 2024, 2:53 p.m.

9.3

CVSS3.1

CVE-2024-42500 -

HPE has identified a denial of service vulnerability in HPE HP-UX System's Network File System (NFSv4) services.

πŸ“… Published: Sept. 9, 2024, 7:22 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-45296 - path-to-regexp outputs backtracking regular expressions

path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. Because JavaScript is single threaded and regex matching runs on the main thread, poor performance will block the event lo…

πŸ“… Published: Sept. 9, 2024, 7:07 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS3.1

CVE-2024-45411 - Twig has a possible sandbox bypass

Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to bypass the sandbox restrictions. This vulnerability is fixed in 1.44.8, 2.16.1, and 3.14.0.

πŸ“… Published: Sept. 9, 2024, 6:20 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:37 a.m.

5.5

CVSS3.1

CVE-2024-45406 - Craft CMS stored XSS in breadcrumb list and title fields

Craft is a content management system (CMS). Craft CMS 5 stored XSS can be triggered by the breadcrumb list and title fields with user input.

πŸ“… Published: Sept. 9, 2024, 4:46 p.m. πŸ”„ Last Modified: Sept. 13, 2024, 3:30 p.m.

6.9

CVSS4.0

CVE-2024-8605 - code-projects Inventory Management Registration Form registration.php cross site scripting

A vulnerability classified as problematic was found in code-projects Inventory Management 1.0. This vulnerability affects unknown code of the file /view/registration.php of the component Registration Form. The manipulation with the input <script>alert(1)</script> leads to cross site scripting. The …

πŸ“… Published: Sept. 9, 2024, 4 p.m. πŸ”„ Last Modified: Sept. 13, 2024, 3:31 p.m.

6.9

CVSS4.0

CVE-2024-8604 - SourceCodester Online Food Ordering System Create an Account Page index.php cross site scripting

A vulnerability classified as problematic has been found in SourceCodester Online Food Ordering System 2.0. This affects an unknown part of the file index.php of the component Create an Account Page. The manipulation of the argument First Name/Last Name leads to cross site scripting. It is possible…

πŸ“… Published: Sept. 9, 2024, 4 p.m. πŸ”„ Last Modified: March 30, 2026, 6:15 p.m.

2.4

CVSS3.1

CVE-2024-8042 - Rapid7 Insight Platform Unauthorized Empty Group Creation

Rapid7 Insight Platform versions between November 2019 and August 14, 2024 suffer from missing authorization issues whereby an attacker can intercept local requests to set the name and description of a new user group. This could potentially lead to an empty user group being added to the incorrect c…

πŸ“… Published: Sept. 9, 2024, 3:02 p.m. πŸ”„ Last Modified: Sept. 17, 2024, 5:25 p.m.
Total resulsts: 349182
Page 8628 of 34,919
Β« previous page Β» next page
Filters