6.1

CVSS3.1

CVE-2024-45176 -

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper input validation, the C-MOR web interface is vulnerable to reflected cross-site scripting (XSS) attacks. It was found out that different functions are prone to reflected cross-site scripting attacks due to insuf…

πŸ“… Published: Sept. 5, 2024, midnight πŸ”„ Last Modified: Sept. 4, 2025, 4:32 p.m.

7.4

CVSS3.1

CVE-2024-44727 -

Sourcecodehero Event Management System1.0 is vulnerable to SQL Injection via the parameter 'username' in /event/admin/login.php.

πŸ“… Published: Sept. 5, 2024, midnight πŸ”„ Last Modified: Sept. 6, 2024, 1:15 p.m.

8.8

CVSS3.1

CVE-2024-45175 -

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Sensitive information is stored in cleartext. It was found out that sensitive information, for example login credentials of cameras, is stored in cleartext. Thus, an attacker with filesystem access, for example exploiting a pat…

πŸ“… Published: Sept. 5, 2024, midnight πŸ”„ Last Modified: Sept. 4, 2025, 4:35 p.m.

9.1

CVSS3.1

CVE-2024-42885 -

SQL Injection vulnerability in ESAFENET CDG 5.6 and before allows an attacker to execute arbitrary code via the id parameter of the data.jsp page.

πŸ“… Published: Sept. 5, 2024, midnight πŸ”„ Last Modified: July 3, 2025, 12:43 p.m.

7.1

CVSS3.1

CVE-2024-45178 -

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is possible to download arbitrary files from the C-MOR system via a path traversal attack. It was found out that different functionalities are vulnerable to path traversal attacks, due …

πŸ“… Published: Sept. 5, 2024, midnight πŸ”„ Last Modified: Sept. 4, 2025, 4:14 p.m.

9.8

CVSS3.1

CVE-2024-45159 -

An issue was discovered in Mbed TLS 3.x before 3.6.1. With TLS 1.3, when a server enables optional authentication of the client, if the client-provided certificate does not have appropriate values in if keyUsage or extKeyUsage extensions, then the return value of mbedtls_ssl_get_verify_result() wou…

πŸ“… Published: Sept. 5, 2024, midnight πŸ”„ Last Modified: March 13, 2025, 8:15 p.m.

7.6

CVSS3.1

CVE-2024-44728 -

Sourcecodehero Event Management System 1.0 allows Stored Cross-Site Scripting via parameters Full Name, Address, Email, and contact# in /clientdetails/admin/regester.php.

πŸ“… Published: Sept. 5, 2024, midnight πŸ”„ Last Modified: Sept. 6, 2024, 1:23 p.m.

6.5

CVSS3.1

CVE-2024-45589 -

RapidIdentity LTS through 2023.0.2 and Cloud through 2024.08.0 improperly restricts excessive authentication attempts and allows a remote attacker to cause a denial of service via the username parameters.

πŸ“… Published: Sept. 5, 2024, midnight πŸ”„ Last Modified: Sept. 12, 2024, 4:54 p.m.

8.8

CVSS3.1

CVE-2024-45173 -

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper privilege management concerning sudo privileges, C-MOR is vulnerable to a privilege escalation attack. The Linux user www-data running the C-MOR web interface can execute some OS commands as root via Sudo withou…

πŸ“… Published: Sept. 5, 2024, midnight πŸ”„ Last Modified: Sept. 4, 2025, 4:32 p.m.

6.1

CVSS3.1

CVE-2024-45429 -

Cross-site scripting vulnerability exists in Advanced Custom Fields versions 6.3.5 and earlier and Advanced Custom Fields Pro versions 6.3.5 and earlier. If an attacker with the 'capability' setting privilege which is set in the product settings stores an arbitrary script in the field label, the sc…

πŸ“… Published: Sept. 4, 2024, 11:07 p.m. πŸ”„ Last Modified: March 25, 2025, 4:15 p.m.
Total resulsts: 349182
Page 8655 of 34,919
Β« previous page Β» next page
Filters