5.3

CVSS4.0

CVE-2024-7077 - Reflected XSS in Semtek Informatics Software's Semtek Sempos

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Semtek Informatics Software Consulting Inc. Semtek Sempos allows Reflected XSS.This issue affects Semtek Sempos: through 31072024.

πŸ“… Published: Sept. 4, 2024, 2:24 p.m. πŸ”„ Last Modified: Sept. 5, 2024, 2:39 p.m.

9.3

CVSS4.0

CVE-2024-7076 - SQLi in Semtek Informatics Software's Semtek Sempos

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Semtek Informatics Software Consulting Inc. Semtek Sempos allows Blind SQL Injection.This issue affects Semtek Sempos: through 31072024.

πŸ“… Published: Sept. 4, 2024, 2:13 p.m. πŸ”„ Last Modified: Sept. 5, 2024, 2:39 p.m.

5.3

CVSS4.0

CVE-2024-8408 - Linksys WRT54G POST Parameter apply.cgi validate_services_port stack-based overflow

A vulnerability was found in Linksys WRT54G 4.21.5. It has been rated as critical. Affected by this issue is the function validate_services_port of the file /apply.cgi of the component POST Parameter Handler. The manipulation of the argument services_array leads to stack-based buffer overflow. The …

πŸ“… Published: Sept. 4, 2024, 2 p.m. πŸ”„ Last Modified: Sept. 5, 2024, 2:41 p.m.

5.3

CVSS4.0

CVE-2024-8407 - alwindoss akademy handlers.go cross site scripting

A vulnerability was found in alwindoss akademy up to 35caccea888ed63d5489e211c99edff1f62efdba. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file cmd/akademy/handler/handlers.go. The manipulation of the argument emailAddress leads to cross si…

πŸ“… Published: Sept. 4, 2024, 2 p.m. πŸ”„ Last Modified: Sept. 5, 2024, 2:48 p.m.

9.8

CVSS3.1

CVE-2024-7012 - Puppet-foreman: an authentication bypass vulnerability exists in foreman

An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to the puppet-foreman configuration. This issue arises from Apache's mod_proxy not properly unsetting headers because of restrictions on underscores in HTTP headers, allowing authen…

πŸ“… Published: Sept. 4, 2024, 1:14 p.m. πŸ”„ Last Modified: Nov. 11, 2025, 3:29 p.m.

9.8

CVSS3.1

CVE-2024-7923 - Puppet-pulpcore: an authentication bypass vulnerability exists in pulpcore

An authentication bypass vulnerability has been identified in Pulpcore when deployed with Gunicorn versions prior to 22.0, due to the puppet-pulpcore configuration. This issue arises from Apache's mod_proxy not properly unsetting headers because of restrictions on underscores in HTTP headers, allow…

πŸ“… Published: Sept. 4, 2024, 1 p.m. πŸ”„ Last Modified: Nov. 11, 2025, 4:12 p.m.

7.8

CVSS3.1

CVE-2024-7834 - Local privilege escalation in Overwolf

A local privilege escalation is caused by Overwolf loading and executing certain dynamic link library files from a user-writeable folder in SYSTEM context on launch. This allows an attacker with unprivileged access to the system to run arbitrary code with SYSTEM privileges by placing a malicious .d…

πŸ“… Published: Sept. 4, 2024, 12:35 p.m. πŸ”„ Last Modified: Sept. 5, 2024, 5:52 p.m.

0.0

CVSS3.1

CVE-2024-8421 - golang.org/x/net/http2: Multiple HTTP/2 enabled web servers (Rapid Reset Attack)

Red Hat Product Security has come to the conclusion that this CVE is not needed.

πŸ“… Published: Sept. 4, 2024, noon πŸ”„ Last Modified: Oct. 30, 2024, 10:15 p.m.

5.4

CVSS3.1

CVE-2024-8413 - Cross Site Scripting (XSS) in Raspcontrol

Cross Site Scripting (XSS) vulnerability through the action parameter in index.php. Affected product codebase https://github.com/Bioshox/Raspcontrol and forks such as https://github.com/harmon25/raspcontrol . An attacker could exploit this vulnerability by sending a specially crafted JavaScript …

πŸ“… Published: Sept. 4, 2024, 10:31 a.m. πŸ”„ Last Modified: Sept. 5, 2024, 5:40 p.m.

7.5

CVSS3.1

CVE-2024-8418 - Containers/aardvark-dns: tcp query handling flaw in aardvark-dns leading to denial of service

A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP DNS queries. An attacker can exploit this flaw by keeping a TCP connection open indefinitely, causing the server to become unresponsive and resulting in other DNS queries timing o…

πŸ“… Published: Sept. 4, 2024, 10 a.m. πŸ”„ Last Modified: Nov. 20, 2025, 8:57 p.m.
Total resulsts: 349182
Page 8659 of 34,919
Β« previous page Β» next page
Filters