5.3

CVSS3.1

CVE-2024-45052 - Fides Webserver Authentication Timing-Based Username Enumeration Vulnerability

Fides is an open-source privacy engineering platform. Prior to version 2.44.0, a timing-based username enumeration vulnerability exists in Fides Webserver authentication. This vulnerability allows an unauthenticated attacker to determine the existence of valid usernames by analyzing the time it tak…

πŸ“… Published: Sept. 4, 2024, 3:43 p.m. πŸ”„ Last Modified: Sept. 6, 2024, 6:18 p.m.

7.1

CVSS3.1

CVE-2024-45050 - Ringer Server Does Not Check Members When Loading Messages

Ringer server is the server code for the Ringer messaging app. Prior to version 1.3.1, there is an issue with the messages loading route where Ringer Server does not check to ensure that the user loading the conversation is actually a member of that conversation. This allows any user with a Lif Acc…

πŸ“… Published: Sept. 4, 2024, 3:39 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.4

CVSS3.1

CVE-2024-43405 - Nuclei Template Signature Verification Bypass

Nuclei is a vulnerability scanner powered by YAML based templates. Starting in version 3.0.0 and prior to version 3.3.2, a vulnerability in Nuclei's template signature verification system could allow an attacker to bypass the signature check and possibly execute malicious code via custom code templ…

πŸ“… Published: Sept. 4, 2024, 3:36 p.m. πŸ”„ Last Modified: Oct. 1, 2024, 3:37 p.m.

5.3

CVSS4.0

CVE-2024-8412 - LinuxOSsk Shakal-NG views.py redirect

A vulnerability, which was classified as problematic, was found in LinuxOSsk Shakal-NG up to 1.3.3. Affected is an unknown function of the file comments/views.py. The manipulation of the argument next leads to open redirect. It is possible to launch the attack remotely. The name of the patch is ebd…

πŸ“… Published: Sept. 4, 2024, 3:31 p.m. πŸ”„ Last Modified: Sept. 12, 2024, 4:47 p.m.

8.2

CVSS3.1

CVE-2024-43402 - Rust OS Command Injection/Argument Injection vulnerability

Rust is a programming language. The fix for CVE-2024-24576, where `std::process::Command` incorrectly escaped arguments when invoking batch files on Windows, was incomplete. Prior to Rust version 1.81.0, it was possible to bypass the fix when the batch file name had trailing whitespace or periods (…

πŸ“… Published: Sept. 4, 2024, 3:29 p.m. πŸ”„ Last Modified: Oct. 1, 2024, 3:12 p.m.

6.9

CVSS4.0

CVE-2024-8391 - Eclipse Vert.x gRPC server does not limit the maximum message size

In Eclipse Vert.x version 4.3.0 to 4.5.9, the gRPC server does not limit the maximum length of message payload (Maven GAV: io.vertx:vertx-grpc-server and io.vertx:vertx-grpc-client).Β  This is fixed in the 4.5.10 version.Β  Note this does not affect the Vert.x gRPC server based grpc-java and …

πŸ“… Published: Sept. 4, 2024, 3:27 p.m. πŸ”„ Last Modified: Sept. 12, 2024, 4:44 p.m.

5.1

CVSS4.0

CVE-2024-8411 - ABCD ABCD2 buscar_integrada.php cross site scripting

A vulnerability was determined in ABCD ABCD2 up to 2.2.0-beta-1. Impacted is an unknown function of the file /buscar_integrada.php. Executing a manipulation of the argument Sub_Expresion can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been publicly di…

πŸ“… Published: Sept. 4, 2024, 3 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:28 p.m.

5.3

CVSS4.0

CVE-2024-8410 - ABCD ABCD2 otros_sitios.php path traversal

A vulnerability classified as problematic was found in ABCD ABCD2 up to 2.2.0-beta-1. This vulnerability affects unknown code of the file /abcd/opac/php/otros_sitios.php. The manipulation of the argument sitio leads to path traversal. The attack can be initiated remotely. The exploit has been discl…

πŸ“… Published: Sept. 4, 2024, 3 p.m. πŸ”„ Last Modified: Sept. 5, 2024, 2:20 p.m.

9.2

CVSS4.0

CVE-2024-7078 - Unauthenticate SQLi in Semtek Informatics Software's Semtek Sempos

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Semtek Informatics Software Consulting Inc. Semtek Sempos allows SQL Injection.This issue affects Semtek Sempos: through 31072024.

πŸ“… Published: Sept. 4, 2024, 2:36 p.m. πŸ”„ Last Modified: Sept. 5, 2024, 2:38 p.m.

5.3

CVSS4.0

CVE-2024-8409 - ABCD ABCD2 show_image.php path traversal

A vulnerability classified as problematic has been found in ABCD ABCD2 up to 2.2.0-beta-1. This affects an unknown part of the file /common/show_image.php. The manipulation of the argument image leads to path traversal: '../filedir'. It is possible to initiate the attack remotely. The exploit has b…

πŸ“… Published: Sept. 4, 2024, 2:31 p.m. πŸ”„ Last Modified: Sept. 5, 2024, 2:20 p.m.
Total resulsts: 349182
Page 8658 of 34,919
Β« previous page Β» next page
Filters