8.3

CVSS3.1

CVE-2024-45041 - External Secrets Operator vulnerable to privilege escalation

External Secrets Operator is a Kubernetes operator that integrates external secret management systems. The external-secrets has a deployment called default-external-secrets-cert-controller, which is bound with a same-name ClusterRole. This ClusterRole has "get/list" verbs of secrets resources. It a…

πŸ“… Published: Sept. 9, 2024, 2:54 p.m. πŸ”„ Last Modified: Sept. 18, 2024, 5:31 p.m.

4.8

CVSS3.1

CVE-2024-8373 - AngularJS improper sanitization in '<source>' element

Improper sanitization of the value of the [srcset] attribute in <source> HTML elements in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects all vers…

πŸ“… Published: Sept. 9, 2024, 2:48 p.m. πŸ”„ Last Modified: Nov. 20, 2025, 6 p.m.

4.8

CVSS3.1

CVE-2024-8372 - AngularJS improper sanitization in 'srcset' attribute

Improper sanitization of the value of the 'srcset' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects AngularJS versions 1.3.0-rc.4 and …

πŸ“… Published: Sept. 9, 2024, 2:46 p.m. πŸ”„ Last Modified: Nov. 20, 2025, 6 p.m.

9.7

CVSS3.1

CVE-2024-40643 - Joplin has a parsing error leading to Cross-site Scripting (XSS)

Joplin is a free, open source note taking and to-do application. Joplin fails to take into account that "<" followed by a non letter character will not be considered html. As such it is possible to do an XSS by putting an "illegal" tag within a tag.

πŸ“… Published: Sept. 9, 2024, 2:28 p.m. πŸ”„ Last Modified: Sept. 17, 2024, 6:03 p.m.

0.0

CVE-2024-45804 -

This CVE is a duplicate of another CVE.

πŸ“… Published: Sept. 9, 2024, 2:23 p.m. πŸ”„ Last Modified: Sept. 17, 2024, 6:15 p.m.

7.1

CVSS4.0

CVE-2024-7015 - Improper Authentication in Profelis Informatics and Consulting's PassBOX

Missing Authentication for Critical Function vulnerability in Profelis Informatics and Consulting PassBox allows Authentication Abuse.This issue affects PassBox: before v1.2.

πŸ“… Published: Sept. 9, 2024, 2:03 p.m. πŸ”„ Last Modified: Oct. 14, 2025, 1:15 p.m.

4.8

CVSS3.1

CVE-2024-7318 - Keycloak-core: one time passcode (otp) is valid longer than expiration timeseverity

A vulnerability was found in Keycloak. Expired OTP codes are still usable when using FreeOTP when the OTP token period is set to 30 seconds (default). Instead of expiring and deemed unusable around 30 seconds in, the tokens are valid for an additional 30 seconds totaling 1 minute. A one time passc…

πŸ“… Published: Sept. 9, 2024, 1:55 p.m. πŸ”„ Last Modified: Jan. 26, 2026, 3:11 p.m.

6.1

CVSS3.1

CVE-2024-7260 - Keycloak-core: open redirect on account page

An open redirect vulnerability was found in Keycloak. A specially crafted URL can be constructed where the referrer and referrer_uri parameters are made to trick a user to visit a malicious webpage. A trusted URL can trick users and automation into believing that the URL is safe, when, in fact, it …

πŸ“… Published: Sept. 9, 2024, 1:55 p.m. πŸ”„ Last Modified: Jan. 23, 2026, 5 p.m.

7.1

CVSS3.1

CVE-2024-7341 - Wildfly-elytron: org.keycloak/keycloak-services: session fixation in elytron saml adapters

A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie are not changed at login time, even when the turnOffChangeSessionIdOnLogin option is configured. This flaw allows an attacker who hijacks the current session before authentication…

πŸ“… Published: Sept. 9, 2024, 1:48 p.m. πŸ”„ Last Modified: April 1, 2026, 1:28 p.m.

6.3

CVSS4.0

CVE-2024-6572 - Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and f…

Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem' in Checkmk before Checkmk 2.3.0p15, 2.2.0p33, 2.1.0p48 and 2.0.0 (EOL) allows man-in-the-middle attackers to intercept traffic

πŸ“… Published: Sept. 9, 2024, 9:39 a.m. πŸ”„ Last Modified: Aug. 25, 2025, 2:53 p.m.
Total resulsts: 349182
Page 8629 of 34,919
Β« previous page Β» next page
Filters