6.5

CVSS3.1

CVE-2024-38810 - Missing Authorization When Using @AuthorizeReturnObject

Missing Authorization When Using @AuthorizeReturnObject in Spring Security 6.3.0 and 6.3.1 allows attacker to render security annotations inaffective.

πŸ“… Published: Aug. 20, 2024, midnight πŸ”„ Last Modified: Feb. 28, 2025, 10:37 p.m.

9.8

CVSS3.1

CVE-2024-42919 -

eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport.

πŸ“… Published: Aug. 20, 2024, midnight πŸ”„ Last Modified: Nov. 12, 2025, 3:44 p.m.

8.8

CVSS3.1

CVE-2024-42566 -

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the password parameter at login.php

πŸ“… Published: Aug. 20, 2024, midnight πŸ”„ Last Modified: Aug. 21, 2024, 1:47 p.m.

9.8

CVSS3.1

CVE-2024-42562 -

Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at preview.php.

πŸ“… Published: Aug. 20, 2024, midnight πŸ”„ Last Modified: June 5, 2025, 8:17 p.m.

8.8

CVSS3.1

CVE-2024-42621 -

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_editor.php

πŸ“… Published: Aug. 20, 2024, midnight πŸ”„ Last Modified: Aug. 21, 2024, 12:50 p.m.

5.7

CVSS3.1

CVE-2024-42603 -

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=clearall

πŸ“… Published: Aug. 20, 2024, midnight πŸ”„ Last Modified: Aug. 21, 2024, 1:21 p.m.

9.8

CVSS3.1

CVE-2024-42567 -

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the sid parameter at /search.php?action=2.

πŸ“… Published: Aug. 20, 2024, midnight πŸ”„ Last Modified: Aug. 21, 2024, 1:46 p.m.

9.8

CVSS3.1

CVE-2024-42565 -

ERP commit 44bd04 was discovered to contain a SQL injection vulnerability via the id parameter at /index.php/basedata/contact/delete?action=delete.

πŸ“… Published: Aug. 20, 2024, midnight πŸ”„ Last Modified: June 17, 2025, 8:07 p.m.

8.8

CVSS3.1

CVE-2024-31842 -

An issue was discovered in Italtel Embrace 1.6.4. The web application inserts the access token of an authenticated user inside GET requests. The query string for the URL could be saved in the browser's history, passed through Referers to other web sites, stored in web logs, or otherwise recorded in…

πŸ“… Published: Aug. 20, 2024, midnight πŸ”„ Last Modified: Oct. 29, 2024, 9:35 p.m.

4.7

CVSS3.1

CVE-2024-43866 - net/mlx5: Always drain health in shutdown callback

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Always drain health in shutdown callback There is no point in recovery during device shutdown. if health work started need to wait for it to avoid races and NULL pointer access. Hence, drain health WQ on shutdown callb…

πŸ“… Published: Aug. 20, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 10:18 p.m.
Total resulsts: 349182
Page 8795 of 34,919
Β« previous page Β» next page
Filters