5.4

CVSS3.1

CVE-2024-25837 -

A stored cross-site scripting (XSS) vulnerability in October CMS Bloghub Plugin v1.3.8 and lower allows attackers to execute arbitrary web scripts or HTML via a crafted payload into the Comments section.

πŸ“… Published: Aug. 16, 2024, midnight πŸ”„ Last Modified: April 28, 2025, 2:06 p.m.

7.8

CVSS3.1

CVE-2024-43378 - calamares-nixos-extensions LUKS keyfile exposure regression on legacy BIOS systems

calamares-nixos-extensions provides Calamares branding and modules for NixOS, a distribution of GNU/Linux. Users who installed NixOS through the graphical installer who used manual disk partitioning to create a setup where the system was booted via legacy BIOS rather than UEFI; some disk partitions…

πŸ“… Published: Aug. 15, 2024, 11:53 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.5

CVSS3.1

CVE-2024-43374 - Vim heap-use-after-free in src/arglist.c:207

The UNIX editor Vim prior to version 9.1.0678 has a use-after-free error in argument list handling. When adding a new file to the argument list, this triggers `Buf*` autocommands. If in such an autocommand the buffer that was just opened is closed (including the window where it is shown), this caus…

πŸ“… Published: Aug. 15, 2024, 11:47 p.m. πŸ”„ Last Modified: Aug. 25, 2025, 1:51 p.m.

7.2

CVSS3.1

CVE-2024-43370 - gettext.js vulnerable to cross-site scripting (XSS)

gettext.js is a GNU gettext port for node and the browser. There is a cross-site scripting (XSS) injection if `.po` dictionary definition files are corrupted. This vulnerability has been patched in version 2.0.3. As a workaround, control the origin of the definition catalog to prevent the use of th…

πŸ“… Published: Aug. 15, 2024, 11:44 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2024-7849 - D-Link DNS-1550-04 photocenter_mgr.cgi cgi_create_album buffer overflow

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1…

πŸ“… Published: Aug. 15, 2024, 11:31 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-7845 - SourceCodester Online Graduate Tracer System fetch_it.php sql injection

A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /tracking/admin/fetch_it.php. The manipulation of the argument request leads to sql injection. The attack may be launched remote…

πŸ“… Published: Aug. 15, 2024, 11:31 p.m. πŸ”„ Last Modified: Feb. 18, 2025, 5:39 p.m.

7.2

CVSS3.1

CVE-2024-43369 - Persistent Cross-site Scripting in Ibexa RichText Field Type

Ibexa RichText Field Type is a Field Type for supporting rich formatted text stored in a structured XML format. In versions on the 4.6 branch prior to 4.6.10, the validator for the RichText fieldtype blocklists `javascript:` and `vbscript:` in links to prevent XSS. This can leave other options open…

πŸ“… Published: Aug. 15, 2024, 11:17 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-7844 - SourceCodester Online Graduate Tracer System add_acc.php cross site scripting

A vulnerability has been found in SourceCodester Online Graduate Tracer System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /tracking/admin/add_acc.php. The manipulation of the argument name/user/position leads to cross site scripting. Th…

πŸ“… Published: Aug. 15, 2024, 11 p.m. πŸ”„ Last Modified: Feb. 18, 2025, 5:38 p.m.

6.9

CVSS4.0

CVE-2024-7843 - SourceCodester Online Graduate Tracer System exportcs.php information disclosure

A vulnerability, which was classified as problematic, was found in SourceCodester Online Graduate Tracer System 1.0. Affected is an unknown function of the file /tracking/admin/exportcs.php. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The exploit …

πŸ“… Published: Aug. 15, 2024, 10:31 p.m. πŸ”„ Last Modified: Feb. 18, 2025, 5:39 p.m.

7.8

CVSS3.1

CVE-2024-34743 -

In setTransactionState of SurfaceFlinger.cpp, there is a possible way to perform tapjacking due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

πŸ“… Published: Aug. 15, 2024, 9:56 p.m. πŸ”„ Last Modified: Dec. 17, 2024, 5:47 p.m.
Total resulsts: 349182
Page 8833 of 34,919
Β« previous page Β» next page
Filters