10

CVSS3.1

CVE-2024-42489 - Pro Macros Remote Code Execution via Viewpdf and similar macros

Pro Macros provides XWiki rendering macros. Missing escaping in the Viewpdf macro allows any user with view right on the `CKEditor.HTMLConverter` page or edit or comment right on any page to perform remote code execution. Other macros like Viewppt are vulnerable to the same kind of attack. This vul…

πŸ“… Published: Aug. 12, 2024, 3:49 p.m. πŸ”„ Last Modified: Sept. 16, 2024, 7:46 p.m.

7.5

CVSS3.1

CVE-2024-42485 - Filament Excel Vulnerable to Path Traversal Attack on Export Download Endpoint

Filament Excel enables excel export for Filament admin resources. The export download route `/filament-excel/{path}` allowed downloading any file without login when the webserver allows `../` in the URL. Patched with Version v2.3.3.

πŸ“… Published: Aug. 12, 2024, 3:39 p.m. πŸ”„ Last Modified: Sept. 18, 2024, 6:31 p.m.

4.8

CVSS3.1

CVE-2024-42482 - fish-shop/syntax-check Improper Neutralization of Delimiters

fish-shop/syntax-check is a GitHub action for syntax checking fish shell files. Improper neutralization of delimiters in the `pattern` input (specifically the command separator `;` and command substitution characters `(` and `)`) mean that arbitrary command injection is possible by modification of …

πŸ“… Published: Aug. 12, 2024, 3:35 p.m. πŸ”„ Last Modified: Sept. 17, 2024, 12:20 p.m.

7.5

CVSS3.1

CVE-2024-42481 - Complete crash of host system due to calculateDirectorySize in skyportd

Skyport Daemon (skyportd) is the daemon for the Skyport Panel. By making thousands of folders & files (easy due to skyport's lack of rate limiting on createFolder. createFile), skyportd in a lot of cases will cause 100% CPU usage and an OOM, probably crashing the system. This is fixed in 0.2.2.

πŸ“… Published: Aug. 12, 2024, 3:30 p.m. πŸ”„ Last Modified: Sept. 16, 2024, 5:10 p.m.

8.1

CVSS3.1

CVE-2024-42480 - Kamaji's RBAC Roles for `etcd` are not disjunct

Kamaji is the Hosted Control Plane Manager for Kubernetes. In versions 1.0.0 and earlier, Kamaji uses an "open at the top" range definition in RBAC for etcd roles leading to some TCPs API servers being able to read, write, and delete the data of other control planes. This vulnerability is fixed in …

πŸ“… Published: Aug. 12, 2024, 3:21 p.m. πŸ”„ Last Modified: Aug. 16, 2024, 4:24 p.m.

10

CVSS3.1

CVE-2024-42479 - llama.cpp allows write-what-where in rpc_server::set_tensor

llama.cpp provides LLM inference in C/C++. The unsafe `data` pointer member in the `rpc_tensor` structure can cause arbitrary address writing. This vulnerability is fixed in b3561.

πŸ“… Published: Aug. 12, 2024, 3:07 p.m. πŸ”„ Last Modified: April 27, 2026, 5:44 p.m.

6.1

CVSS3.1

CVE-2024-21550 -

SteVe is an open platform that implements different version of the OCPP protocol for Electric Vehicle charge points, acting as a central server for management of registered charge points. Attackers can inject arbitrary HTML and Javascript code via WebSockets leading to persistent Cross-Site Scripti…

πŸ“… Published: Aug. 12, 2024, 2:54 p.m. πŸ”„ Last Modified: Aug. 13, 2024, 5:33 p.m.

10

CVSS4.0

CVE-2024-6917 - RCE in Veribilim Software's Veribase Order Management

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Veribilim Software Veribase Order Management allows OS Command Injection.This issue affects Veribase Order Management: before v4.010.2.

πŸ“… Published: Aug. 12, 2024, 2:51 p.m. πŸ”„ Last Modified: Aug. 13, 2024, 5:52 p.m.

9.8

CVSS3.1

CVE-2024-38530 - Open eClass Platform allows Arbitrary File Upload in "modules/h5p/save.php"

The Open eClass platform (formerly known as GUnet eClass) is a complete Course Management System. An arbitrary file upload vulnerability in the "save" functionality of the H5P module enables unauthenticated users to upload arbitrary files on the server's filesystem. This may lead in unrestricted RC…

πŸ“… Published: Aug. 12, 2024, 2:50 p.m. πŸ”„ Last Modified: Aug. 13, 2024, 5:17 p.m.

6.4

CVSS3.1

CVE-2024-6639 - MDx <= 2.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via mdx_list_item Shortcode

The MDx theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mdx_list_item' shortcode in all versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…

πŸ“… Published: Aug. 12, 2024, 1:49 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347741
Page 8750 of 34,775
Β« previous page Β» next page
Filters