6.1

CVSS3.1

CVE-2024-27184 - [20240801] - Core - Inadequate validation of internal URLs

Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not..

๐Ÿ“… Published: Aug. 20, 2024, 4:03 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 8:59 p.m.

6.1

CVSS3.1

CVE-2024-40743 - [20240805] - Core - XSS vectors in Outputfilter::strip* methods

The stripImages and stripIframes methods didn't properly process inputs, leading to XSS vectors.

๐Ÿ“… Published: Aug. 20, 2024, 4:03 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 8:57 p.m.

7.5

CVSS3.1

CVE-2024-27187 - [20240804] - Core - Improper ACL for backend profile view

Improper Access Controls allows backend users to overwrite their username when disallowed.

๐Ÿ“… Published: Aug. 20, 2024, 4:03 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 8:58 p.m.

6.5

CVSS3.1

CVE-2024-43409 - Ghost's improper authentication allows access to member information and actions

Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information. This security vulnerability is present in Ghost v4.46.0-v5.89.4. v5.89.5 contains a fix for this issue.

๐Ÿ“… Published: Aug. 20, 2024, 3:05 p.m. ๐Ÿ”„ Last Modified: Sept. 3, 2024, 2:58 p.m.

8.8

CVSS3.1

CVE-2024-43406 - LF Edge eKuiper has a SQL Injection in sqlKvStore

LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. A user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. This vulnerability is fixed in 1.14.2.

๐Ÿ“… Published: Aug. 20, 2024, 3 p.m. ๐Ÿ”„ Last Modified: Aug. 26, 2024, 6:30 p.m.

9.8

CVSS3.1

CVE-2024-43404 - Remote Code Execution Vulnerability in MEGABOT

MEGABOT is a fully customized Discord bot for learning and fun. The `/math` command and functionality of MEGABOT versions < 1.5.0 contains a remote code execution vulnerability due to a Python `eval()`. The vulnerability allows an attacker to inject Python code into the `expression` parameter when โ€ฆ

๐Ÿ“… Published: Aug. 20, 2024, 2:55 p.m. ๐Ÿ”„ Last Modified: Aug. 26, 2024, 6:29 p.m.

4.3

CVSS3.1

CVE-2024-43397 - Potential unauthorized access issue in apollo-portal

Apollo is a configuration management system. A vulnerability exists in the synchronization configuration feature that allows users to craft specific requests to bypass permission checks. This exploit enables them to modify a namespace without the necessary permissions. The issue was addressed with โ€ฆ

๐Ÿ“… Published: Aug. 20, 2024, 2:50 p.m. ๐Ÿ”„ Last Modified: Aug. 26, 2024, 6:28 p.m.

5.4

CVSS3.1

CVE-2024-43377 - Umbraco CMS Improper Access Control vulnerability

Umbraco CMS is an ASP.NET CMS. An authenticated user can access a few unintended endpoints. This issue is fixed in 14.1.2.

๐Ÿ“… Published: Aug. 20, 2024, 2:43 p.m. ๐Ÿ”„ Last Modified: Sept. 3, 2024, 5:05 p.m.

4.3

CVSS3.1

CVE-2024-43376 - Umbraco CMS vulnerable to Generation of Error Message Containing Sensitive Information

Umbraco is an ASP.NET CMS. Some endpoints in the Management API can return stack trace information, even when Umbraco is not in debug mode. This vulnerability is fixed in 14.1.2.

๐Ÿ“… Published: Aug. 20, 2024, 2:40 p.m. ๐Ÿ”„ Last Modified: Aug. 26, 2024, 6:24 p.m.

4.1

CVSS3.1

CVE-2024-42369 - A room with itself as a its predecessor will freeze matrix-js-sdk

matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. A malicious homeserver can craft a room or room structure such that the predecessors form a cycle. The matrix-js-sdk's getRoomUpgradeHistory function will infinitely recurse in this case, causing the code to hang. This mโ€ฆ

๐Ÿ“… Published: Aug. 20, 2024, 2:37 p.m. ๐Ÿ”„ Last Modified: Sept. 3, 2024, 5:06 p.m.
Total resulsts: 349182
Page 8787 of 34,919
ยซ previous page ยป next page
Filters