8.8

CVSS3.1

CVE-2024-8362 - chromium-browser: Use after free in WebAudio

Use after free in WebAudio in Google Chrome prior to 128.0.6613.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: Sept. 3, 2024, 10:40 p.m. πŸ”„ Last Modified: Jan. 2, 2025, 5:37 p.m.

8.8

CVSS3.1

CVE-2024-45394 - Secret encryption vulnerable to brute-force attacks

Authenticator is a browser extension that generates two-step verification codes. In versions 7.0.0 and below, encryption keys for user data were stored encrypted at-rest using only AES-256 and the EVP_BytesToKey KDF. Therefore, attackers with a copy of a user's data are able to brute-force the user…

πŸ“… Published: Sept. 3, 2024, 8:15 p.m. πŸ”„ Last Modified: Oct. 9, 2024, 3:15 p.m.

4.7

CVSS3.1

CVE-2024-8399 -

Websites could utilize Javascript links to spoof URL addresses in the Focus navigation bar This vulnerability affects Focus for iOS < 130.

πŸ“… Published: Sept. 3, 2024, 8:07 p.m. πŸ”„ Last Modified: March 19, 2025, 4:15 p.m.

7.5

CVSS3.1

CVE-2024-45391 - Tina search token leak via lock file in TinaCMS

Tina is an open-source content management system (CMS). Sites building with Tina CMS's command line interface (CLI) prior to version 1.6.2 that use a search token may be vulnerable to the search token being leaked via lock file (tina-lock.json). Administrators of Tina-enabled websites with search s…

πŸ“… Published: Sept. 3, 2024, 7:43 p.m. πŸ”„ Last Modified: March 13, 2026, 7:37 p.m.

6.5

CVSS3.1

CVE-2024-4629 - Keycloak: potential bypass of brute force protection

A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the timing of login attempts. By initiating multiple login requests simultaneously, attackers can exceed the configured limits for failed attempts before the system locks them out. This …

πŸ“… Published: Sept. 3, 2024, 7:38 p.m. πŸ”„ Last Modified: March 26, 2026, 11:13 p.m.

7.3

CVSS3.1

CVE-2024-45390 - @blakeembrey/template vulnerable to code injection when attacker controls template input

@blakeembrey/template is a string template library. Prior to version 1.2.0, it is possible to inject and run code within the template if the attacker has access to write the template name. Version 1.2.0 contains a patch. As a workaround, don't pass untrusted input as the template display name, or d…

πŸ“… Published: Sept. 3, 2024, 7:37 p.m. πŸ”„ Last Modified: Sept. 12, 2024, 8:15 p.m.

6.4

CVSS3.1

CVE-2024-45389 - Pagefind DOM clobbering could escalate to Cross-site Scripting (XSS)

Pagefind, a fully static search library, initializes its dynamic JavaScript and WebAssembly files relative to the location of the first script the user loads. This information is gathered by looking up the value of `document.currentScript.src`. Prior to Pagefind version 1.1.1, it is possible to "cl…

πŸ“… Published: Sept. 3, 2024, 7:30 p.m. πŸ”„ Last Modified: Oct. 14, 2025, 2:44 p.m.

8.8

CVSS3.1

CVE-2024-45307 - SudoBot missing authorization check in `-config` command

SudoBot, a Discord moderation bot, is vulnerable to privilege escalation and exploit of the `-config` command in versions prior to 9.26.7. Anyone is theoretically able to update any configuration of the bot and potentially gain control over the bot's settings. Every version of v9 before v9.26.7 is …

πŸ“… Published: Sept. 3, 2024, 7:01 p.m. πŸ”„ Last Modified: Sept. 7, 2024, 1:34 a.m.

4.9

CVSS3.1

CVE-2024-43803 - BMO can expose particularly named secrets from other namespaces via BMH CRD

The Bare Metal Operator (BMO) implements a Kubernetes API for managing bare metal hosts in Metal3. The `BareMetalHost` (BMH) CRD allows the `userData`, `metaData`, and `networkData` for the provisioned host to be specified as links to Kubernetes Secrets. There are fields for both the `Name` and `Na…

πŸ“… Published: Sept. 3, 2024, 6:56 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.5

CVSS3.1

CVE-2024-43413 - Xibo CMS XSS vulnerability using DataSet HTML columns

Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cross-site scripting vulnerability in Xibo CMS allows authorized users to execute JavaScript via the DataSet functionality. Users can design a DataSet with a HTML column which conta…

πŸ“… Published: Sept. 3, 2024, 6:52 p.m. πŸ”„ Last Modified: Sept. 12, 2024, 8:18 p.m.
Total resulsts: 349182
Page 8674 of 34,919
Β« previous page Β» next page
Filters