6.5

CVSS3.1

CVE-2024-7209 - CVE-2024-7209

A vulnerability exists in the use of shared SPF records in multi-tenant hosting providers, allowing attackers to use network authorization to be abused to spoof the email identify of the sender.

πŸ“… Published: July 30, 2024, 5:01 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2023-26288 - IBM Aspera Orchestrator session fixation

IBM Aspera Orchestrator 4.0.1 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 248477.

πŸ“… Published: July 30, 2024, 5:01 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 7:51 a.m.

6.5

CVSS3.1

CVE-2023-38001 - IBM Aspera Orchestrator cross-site request forgery

IBM Aspera Orchestrator 4.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 260206.

πŸ“… Published: July 30, 2024, 4:54 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 8:12 a.m.

5.4

CVSS3.1

CVE-2023-26289 - IBM Aspera Orchestrator HTTP header injection

IBM Aspera Orchestrator 4.0.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Forc…

πŸ“… Published: July 30, 2024, 4:50 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 7:51 a.m.

6.5

CVSS3.1

CVE-2024-41944 - Sensitive Information Disclosure abusing SQL Injection in Xibo CMS proof of play report

Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the `report/data/proofofplayReport` API route inside the CMS. This allows an authenticated user to to obtain and modify arbitrary data from the Xibo database by injecting specially crafted values in to the `…

πŸ“… Published: July 30, 2024, 4:24 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-7297 - Langflow Privilege Escalation

Langflow versions prior to 1.0.13 suffer from a Privilege Escalation vulnerability, allowing a remote and low privileged attacker to gain super admin privileges by performing a mass assignment request on the '/api/v1/users' endpoint.

πŸ“… Published: July 30, 2024, 4:13 p.m. πŸ”„ Last Modified: March 27, 2026, 3:51 p.m.

6.5

CVSS3.1

CVE-2024-41804 - Xibo allows Sensitive Information Disclosure abusing SQL Injection in Xibo CMS DataSet Column Formu…

Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API route inside the CMS responsible for Adding/Editing DataSet Column Formulas. This allows an authenticated user to to obtain and modify arbitrary data from the Xibo database by injecting specially cra…

πŸ“… Published: July 30, 2024, 3:51 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:33 a.m.

8.1

CVSS3.1

CVE-2024-41802 - Xibo allows Sensitive Information Disclosure abusing SQL Injection in Xibo CMS DataSet Data Import

Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API routes inside the CMS responsible for Filtering DataSets. This allows an authenticated user to to obtain and modify arbitrary data from the Xibo database by injecting specially crafted values in to t…

πŸ“… Published: July 30, 2024, 3:49 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:33 a.m.

4.9

CVSS3.1

CVE-2024-41803 - Xibo allows Sensitive Information Disclosure abusing SQL Injection in Xibo CMS DataSet Filter

Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API routes inside the CMS responsible for Filtering DataSets. This allows an authenticated user to to obtain arbitrary data from the Xibo database by injecting specially crafted values in to the API for …

πŸ“… Published: July 30, 2024, 3:49 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:33 a.m.

0.0

CVE-2024-7298 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: July 30, 2024, 3:30 p.m. πŸ”„ Last Modified: Feb. 11, 2025, 2:15 a.m.
Total resulsts: 346529
Page 8731 of 34,653
Β« previous page Β» next page
Filters