4.1

CVSS3.1

CVE-2024-39732 - IBM Datacap Navigator information disclosure

IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 temporarily stores data from different environments that could be obtained by a malicious user. IBM X-Force ID: 295791.

πŸ“… Published: July 14, 2024, 12:39 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:28 a.m.

4.3

CVSS3.1

CVE-2024-39734 - IBM Datacap Navigator information disclosure

IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent t…

πŸ“… Published: July 14, 2024, 12:38 p.m. πŸ”„ Last Modified: March 25, 2025, 5:15 p.m.

5.3

CVSS4.0

CVE-2024-6730 - Nanjing Xingyuantu Technology SparkShop uploadFile unrestricted upload

A vulnerability was found in Nanjing Xingyuantu Technology SparkShop up to 1.1.6. It has been rated as critical. This issue affects some unknown processing of the file /api/Common/uploadFile. The manipulation of the argument file leads to unrestricted upload. The attack may be initiated remotely. T…

πŸ“… Published: July 14, 2024, 1:31 a.m. πŸ”„ Last Modified: July 13, 2025, 9:06 p.m.

5.3

CVSS4.0

CVE-2024-6729 - SourceCodester Kortex Lite Advocate Office Management System add_act.php sql injection

A vulnerability was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /control/add_act.php. The manipulation of the argument aname leads to sql injection. The attack can be initiated remot…

πŸ“… Published: July 14, 2024, 1 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:50 a.m.

5.3

CVSS4.0

CVE-2024-6728 - itsourcecode Tailoring Management System typeedit.php sql injection

A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been classified as critical. This affects an unknown part of the file typeedit.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disc…

πŸ“… Published: July 14, 2024, 12:31 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:50 a.m.

7.8

CVSS3.1

CVE-2023-52885 - SUNRPC: Fix UAF in svc_tcp_listen_data_ready()

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix UAF in svc_tcp_listen_data_ready() After the listener svc_sock is freed, and before invoking svc_tcp_accept() for the established child sock, there is a window that the newsock retaining a freed listener svc_sock in s…

πŸ“… Published: July 14, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 7:45 a.m.

4.3

CVSS3.1

CVE-2024-6465 - WP Links Page <= 4.9.5 - Missing Authorization to Authenticated (Subscriber+) Limited Image Update

The WP Links Page plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wplf_ajax_update_screenshots' function in all versions up to, and including, 4.9.5. This makes it possible for authenticated attackers, with Subscriber-level access an…

πŸ“… Published: July 13, 2024, 11:19 a.m. πŸ”„ Last Modified: April 8, 2026, 5:19 p.m.

4.8

CVSS3.1

CVE-2024-6070 - if-so < 1.8.0.4 - Admin+ Stored XSS

The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in mul…

πŸ“… Published: July 13, 2024, 6 a.m. πŸ”„ Last Modified: May 16, 2025, 1:21 p.m.

6.8

CVSS3.1

CVE-2024-5744 - WP eMember < 10.6.7 - Reflected XSS

The wp-eMember WordPress plugin before 10.6.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

πŸ“… Published: July 13, 2024, 6 a.m. πŸ”„ Last Modified: May 16, 2025, 1:34 p.m.

7.1

CVSS3.1

CVE-2024-5715 - WP eMember < 10.6.7 - Reflected XSS via Member Edit

The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

πŸ“… Published: July 13, 2024, 6 a.m. πŸ”„ Last Modified: May 20, 2025, 6:19 p.m.
Total resulsts: 343980
Page 8634 of 34,398
Β« previous page Β» next page
Filters