5.5

CVSS3.1

CVE-2024-38432 - Matrix – Tafnit v8 CWE-646: Reliance on File Name or Extension of Externally-Supplied File

Matrix Tafnit v8 - CWE-646: Reliance on File Name or Extension of Externally-Supplied File

📅 Published: July 30, 2024, 8:50 a.m. 🔄 Last Modified: Nov. 21, 2024, 9:25 a.m.

5.3

CVSS3.1

CVE-2024-38431 - Matrix Tafnit v8 - CWE-204: Observable Response Discrepancy

Matrix Tafnit v8 - CWE-204: Observable Response Discrepancy

📅 Published: July 30, 2024, 8:48 a.m. 🔄 Last Modified: Nov. 21, 2024, 9:25 a.m.

5.4

CVSS3.1

CVE-2024-38430 - Matrix - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting…

Matrix - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

📅 Published: July 30, 2024, 8:47 a.m. 🔄 Last Modified: Nov. 21, 2024, 9:25 a.m.

7.2

CVSS3.1

CVE-2024-41924 -

Acceptance of extraneous untrusted data with trusted data vulnerability exists in EC-CUBE 4 series. If this vulnerability is exploited, an attacker who obtained the administrative privilege may install an arbitrary PHP package. If the obsolete versions of PHP packages are installed, the product may…

📅 Published: July 30, 2024, 8:45 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-41141 -

Stored cross-site scripting vulnerability exists in EC-CUBE Web API Plugin. When there are multiple users using OAuth Management feature and one of them inputs some crafted value on the OAuth Management page, an arbitrary script may be executed on the web browser of the other user who accessed the …

📅 Published: July 30, 2024, 8:45 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-38429 - Matrix - CWE-552: Files or Directories Accessible to External Parties

Matrix Tafnit v8 -  CWE-552: Files or Directories Accessible to External Parties

📅 Published: July 30, 2024, 8:45 a.m. 🔄 Last Modified: Nov. 21, 2024, 9:25 a.m.

6.4

CVSS3.1

CVE-2024-40895 -

FFRI AMC versions 3.4.0 to 3.5.3 and some OEM products that implement/bundle FFRI AMC versions 3.4.0 to 3.5.3 allow a remote unauthenticated attacker to execute arbitrary OS commands when certain conditions are met in an environment where the notification program setting is enabled and the executab…

📅 Published: July 30, 2024, 8:37 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-7225 - SourceCodester Insurance Management System Edit Insurance Policy Page update_policy cross site scri…

A vulnerability was found in SourceCodester Insurance Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /Script/admin/core/update_policy of the component Edit Insurance Policy Page. The manipulation of the argument pname leads to cross site scrip…

📅 Published: July 30, 2024, 8:31 a.m. 🔄 Last Modified: Nov. 21, 2024, 9:51 a.m.

6.1

CVSS3.1

CVE-2024-41693 - Mashov - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

Mashov - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

📅 Published: July 30, 2024, 8:28 a.m. 🔄 Last Modified: May 19, 2025, 12:38 p.m.

9.1

CVSS3.1

CVE-2023-48396 - Apache SeaTunnel Web: Authentication bypass

Web Authentication vulnerability in Apache SeaTunnel. Since the jwt key is hardcoded in the application, an attacker can forge any token to log in any user. Attacker can get secret key in /seatunnel-server/seatunnel-app/src/main/resources/application.yml and then create a token. This issue affects…

📅 Published: July 30, 2024, 8:15 a.m. 🔄 Last Modified: July 10, 2025, 6:49 p.m.
Total resulsts: 346536
Page 8734 of 34,654
« previous page » next page
Filters