5.3

CVSS4.0

CVE-2024-8022 - Genexis Tilgin Home Gateway cross site scripting

A vulnerability was found in Genexis Tilgin Home Gateway 322_AS0500-03_05_13_05. It has been rated as problematic. This issue affects some unknown processing of the file /vood/cgi-bin/vood_view.cgi?lang=EN&act=user/spec_conf&sessionId=86213915328111654515&user=A&message2user=Account%20updated. The …

πŸ“… Published: Aug. 20, 2024, 11:31 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-22281 - Apache Helix Front (UI): Helix front hard-coded secret in the express-session

** UNSUPPORTED WHEN ASSIGNED ** The Apache Helix Front (UI) component contained a hard-coded secret, allowing an attacker to spoof sessions by generating their own fake cookies. This issue affects Apache Helix Front (UI): all versions. As this project is retired, we do not plan to release a versi…

πŸ“… Published: Aug. 20, 2024, 10:11 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 8:55 a.m.

8.8

CVSS3.1

CVE-2024-43403 - Kanister has a potential risk which can be leveraged to make a cluster-level privilege escalation

Kanister is a data protection workflow management tool. The kanister has a deployment called default-kanister-operator, which is bound with a ClusterRole called edit via ClusterRoleBinding. The "edit" ClusterRole is one of Kubernetes default-created ClusterRole, and it has the create/patch/udpate v…

πŸ“… Published: Aug. 20, 2024, 9:16 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-42362 - GHSL-2023-255: HertzBeat Authenticated (user role) RCE via unsafe deserialization in /api/monitors/…

Hertzbeat is an open source, real-time monitoring system. Hertzbeat has an authenticated (user role) RCE via unsafe deserialization in /api/monitors/import. This vulnerability is fixed in 1.6.0.

πŸ“… Published: Aug. 20, 2024, 8:56 p.m. πŸ”„ Last Modified: Aug. 28, 2024, 1:49 p.m.

7.5

CVSS3.1

CVE-2024-42361 - GHSL-2023-256: HertzBeat Authenticated (guest role) SQL injection in /api/monitor/{monitorId}/metri…

Hertzbeat is an open source, real-time monitoring system. Hertzbeat 1.6.0 and earlier declares a /api/monitor/{monitorId}/metric/{metricFull} endpoint to download job metrics. In the process, it executes a SQL query with user-controlled data, allowing for SQL injection.

πŸ“… Published: Aug. 20, 2024, 8:56 p.m. πŸ”„ Last Modified: Sept. 3, 2024, 2:54 p.m.

5.4

CVSS3.1

CVE-2024-43396 - Khoj Vulnerable to Stored Cross-site Scripting In Automate (Preview feature)

Khoj is an application that creates personal AI agents. The Automation feature allows a user to insert arbitrary HTML inside the task instructions, resulting in a Stored XSS. The q parameter for the /api/automation endpoint does not get correctly sanitized when rendered on the page, resulting in th…

πŸ“… Published: Aug. 20, 2024, 8:23 p.m. πŸ”„ Last Modified: Sept. 3, 2024, 6:19 p.m.

8.8

CVSS3.1

CVE-2024-42363 - GHSL-2023-136_Samson

Prior to 3385, the user-controlled role parameter enters the application in the Kubernetes::RoleVerificationsController. The role parameter flows into the RoleConfigFile initializer and then into the Kubernetes::Util.parse_file method where it is unsafely deserialized using the YAML.load_stream met…

πŸ“… Published: Aug. 20, 2024, 8:20 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-41658 - GHSL-2024-036: Reflected XSS in QrCodePage.js

Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earlier, he purchase URL that is created to generate a WechatPay QR code is vulnerable to reflected XSS. When purchasing an item through casdoor, the product page allows you to pay vi…

πŸ“… Published: Aug. 20, 2024, 8:11 p.m. πŸ”„ Last Modified: Aug. 28, 2024, 4:08 p.m.

8.1

CVSS3.1

CVE-2024-41657 - GHSL-2024-035: Casdoor CORS misconfiguration

Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earlier, a logic vulnerability exists in the beego filter CorsFilter that allows any website to make cross domain requests to Casdoor as the logged in user. Due to the a logic error in…

πŸ“… Published: Aug. 20, 2024, 8:11 p.m. πŸ”„ Last Modified: Aug. 28, 2024, 4:13 p.m.

8.1

CVSS3.1

CVE-2024-41659 - GHSL-2024-034: memos CORS Misconfiguration in server.go

memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to true. This may allow an attacking website to make a cross-origin request, allowing the attacker t…

πŸ“… Published: Aug. 20, 2024, 7:54 p.m. πŸ”„ Last Modified: July 10, 2025, 3:36 p.m.
Total resulsts: 349182
Page 8785 of 34,919
Β« previous page Β» next page
Filters