4.7

CVSS3.1

CVE-2024-39694 - Duende IdentityServer Open Redirect vulnerability

Duende IdentityServer is an OpenID Connect and OAuth 2.x framework for ASP.NET Core. It is possible for an attacker to craft malicious Urls that certain functions in IdentityServer will incorrectly treat as local and trusted. If such a Url is returned as a redirect, some browsers will follow it to …

πŸ“… Published: July 31, 2024, 3:44 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-39318 - Ibexa Admin UI vulnerable to DOM-based Cross-site Scripting in file upload widget

The Ibexa Admin UI Bundle contains all the necessary parts to run the Ibexa DXP Back Office interface. The file upload widget is vulnerable to XSS payloads in filenames. Access permission to upload files is required. As such, in most cases only authenticated editors and administrators will have the…

πŸ“… Published: July 31, 2024, 3:38 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2024-41947 - XWiki Platform XSS through conflict resolution

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By creating a conflict when another user with more rights is currently editing a page, it is possible to execute JavaScript snippets on the side of the other user, which compromises the confiden…

πŸ“… Published: July 31, 2024, 3:24 p.m. πŸ”„ Last Modified: Sept. 6, 2024, 8:46 p.m.

10

CVSS3.1

CVE-2024-37901 - XWiki Platform vulnerable to remote code execution from account via SearchSuggestConfigSheet

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit right on any page can perform arbitrary remote code execution by adding instances of `XWiki.SearchSuggestConfig` and `XWiki.SearchSuggestSourceClass` to their user profile or …

πŸ“… Published: July 31, 2024, 3:19 p.m. πŸ”„ Last Modified: Sept. 6, 2024, 8:54 p.m.

6.4

CVSS3.1

CVE-2024-37900 - XWiki Platform vulnerable to Cross-site Scripting through attachment filename in uploader

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When uploading an attachment with a malicious filename, malicious JavaScript code could be executed. This requires a social engineering attack to get the victim into uploading a file with a mali…

πŸ“… Published: July 31, 2024, 3:15 p.m. πŸ”„ Last Modified: Jan. 10, 2025, 4:54 p.m.

4.3

CVSS3.1

CVE-2024-37898 - XWiki Platform vulnerable to document deletion and overwrite from edit

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When a user has view but not edit right on a page in XWiki, that user can delete the page and replace it by a page with new content without having delete right. The previous version of the page …

πŸ“… Published: July 31, 2024, 3:12 p.m. πŸ”„ Last Modified: Sept. 6, 2024, 9:16 p.m.

8.8

CVSS3.1

CVE-2024-7340 - W&B Weave server remote arbitrary file leak and privilege escalation

The Weave server API allows remote users to fetch files from a specific directory, but due to a lack of input validation, it is possible to traverse and leak arbitrary files remotely. In various common scenarios, this allows a low-privileged user to assume the role of the server admin.

πŸ“… Published: July 31, 2024, 3 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.3

CVSS3.1

CVE-2024-37135 -

DM5500 5.16.0.0, contains an information disclosure vulnerability. A local attacker with high privileges could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application …

πŸ“… Published: July 31, 2024, 2 p.m. πŸ”„ Last Modified: Nov. 22, 2024, 6:15 p.m.

3.3

CVSS3.1

CVE-2024-31203 -

A β€œCWE-121: Stack-based Buffer Overflow” in the wd210std.dll dynamic library packaged with the ThermoscanIP installer allows a local attacker to possibly trigger a Denial-of-Service (DoS) condition on the target component.

πŸ“… Published: July 31, 2024, 1:18 p.m. πŸ”„ Last Modified: Sept. 30, 2024, 3:15 p.m.

7.8

CVSS3.1

CVE-2024-31202 -

A β€œCWE-732: Incorrect Permission Assignment for Critical Resource” in the ThermoscanIP installation folder allows a local attacker to perform a Local Privilege Escalation.

πŸ“… Published: July 31, 2024, 1:17 p.m. πŸ”„ Last Modified: Sept. 30, 2024, 3:15 p.m.
Total resulsts: 346685
Page 8737 of 34,669
Β« previous page Β» next page
Filters