4.9

CVSS3.1

CVE-2024-41803 - Xibo allows Sensitive Information Disclosure abusing SQL Injection in Xibo CMS DataSet Filter

Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API routes inside the CMS responsible for Filtering DataSets. This allows an authenticated user to to obtain arbitrary data from the Xibo database by injecting specially crafted values in to the API for …

📅 Published: July 30, 2024, 3:49 p.m. 🔄 Last Modified: Nov. 21, 2024, 9:33 a.m.

0.0

CVE-2024-7298 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

📅 Published: July 30, 2024, 3:30 p.m. 🔄 Last Modified: Feb. 11, 2025, 2:15 a.m.

6.3

CVSS3.1

CVE-2024-41109 - Pimcore vulnerable to disclosure of system and database information behind /admin firewall

Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Navigating to `/admin/index/statistics` with a logged in Pimcore user exposes information about the Pimcore installation, PHP version, MYSQL version, installed bundles and all database tables and their row count in the sy…

📅 Published: July 30, 2024, 2:43 p.m. 🔄 Last Modified: Nov. 4, 2025, 6:01 p.m.

7.1

CVSS4.0

CVE-2024-4188 - Security vulnerability exists in Documentum server cloud releases that could allow access to sensit…

Unprotected Transport of Credentials vulnerability in OpenText™ Documentum™ Server could allow Credential Stuffing.This issue affects Documentum™ Server: from 16.7 through 23.4.

📅 Published: July 30, 2024, 2:35 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-39320 - Discourse allows iframe injection though default site setting

Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, the vulnerability allows an attacker to inject iframes from any domain, bypassing the intended restrictions enforced by the allowed_iframes setting. This vulnerability is fixed in 3.2.5 and 3.3.0.beta5.

📅 Published: July 30, 2024, 2:33 p.m. 🔄 Last Modified: Nov. 21, 2024, 9:27 a.m.

4.9

CVSS3.1

CVE-2024-37299 - Discourse vulnerable to DoS via Tag Group

Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, crafting requests to submit very long tag group names can reduce the availability of a Discourse instance. This vulnerability is fixed in 3.2.5 and 3.3.0.beta5.

📅 Published: July 30, 2024, 2:22 p.m. 🔄 Last Modified: Nov. 21, 2024, 9:23 a.m.

6.3

CVSS3.1

CVE-2024-37165 - Discourse has an XSS via Onebox system

Discourse is an open source discussion platform. Prior to 3.2.3 and 3.3.0.beta3, improperly sanitized Onebox data could lead to an XSS vulnerability in some situations. This vulnerability only affects Discourse instances which have disabled the default Content Security Policy. This vulnerability is…

📅 Published: July 30, 2024, 2:10 p.m. 🔄 Last Modified: Nov. 21, 2024, 9:23 a.m.

9.3

CVSS4.0

CVE-2024-6699 - SQLi in Mikafon Electronic's Mikafon MA7

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mikafon Electronic Inc. Mikafon MA7 allows SQL Injection.This issue affects Mikafon MA7: from v3.0 before v3.1.

📅 Published: July 30, 2024, 12:29 p.m. 🔄 Last Modified: Nov. 21, 2024, 9:50 a.m.

7.2

CVSS4.0

CVE-2024-7127 - XSS in Stackposts - Social Marketing Tool

Improper Neutralization of Input During Web Page Generation vulnerability in Stackposts Social Marketing Tool allows Cross-site Scripting (XSS) attack. By submitting the payload in the username during registration, it can be executed later in the application panel. This could lead to the unauthoris…

📅 Published: July 30, 2024, 11:21 a.m. 🔄 Last Modified: Nov. 21, 2024, 9:50 a.m.

9.8

CVSS3.1

CVE-2024-41702 - SiberianCMS – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Inje…

SiberianCMS - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

📅 Published: July 30, 2024, 9:18 a.m. 🔄 Last Modified: Nov. 21, 2024, 9:33 a.m.
Total resulsts: 346531
Page 8732 of 34,654
« previous page » next page
Filters