4.6

CVSS4.0

CVE-2024-7394 - Concrete CMS version 9.0.0 through 9.3.2 and below 8.5.18 - Stored XSS in getAttributeSetName()

Concrete CMS versions 9 through 9.3.2 and below 8.5.18 are vulnerable to Stored XSS in getAttributeSetName(). A rogue administrator could inject malicious code. The Concrete CMS team gave this a CVSS v4.0 rank of 4.6 with vector https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:N/…

📅 Published: Aug. 8, 2024, 4:31 p.m. 🔄 Last Modified: Sept. 25, 2025, 7:15 p.m.

8.7

CVSS3.1

CVE-2024-0108 -

NVIDIA Jetson Linux contains a vulnerability in NvGPU where error handling paths in GPU MMU mapping code fail to clean up a failed mapping attempt. A successful exploit of this vulnerability may lead to denial of service, code execution, and escalation of privileges.

📅 Published: Aug. 8, 2024, 4:18 p.m. 🔄 Last Modified: Sept. 16, 2024, 7:27 p.m.

3.3

CVSS3.1

CVE-2024-0102 -

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm, where an attacker can cause an out-of-bounds read issue by deceiving a user into reading a malformed ELF file. A successful exploit of this vulnerability might lead to denial of service.

📅 Published: Aug. 8, 2024, 4:12 p.m. 🔄 Last Modified: Sept. 16, 2024, 7:37 p.m.

4.2

CVSS3.1

CVE-2024-7480 - Improper access control in Avaya Aura System Manager

An Improper access control vulnerability was found in Avaya Aura System Manager which could allow a command-line interface (CLI) user with administrative privileges to read arbitrary files on the system. Affected versions include 10.1.x.x and 10.2.x.x. Versions prior to 10.1 are end of manufacturer…

📅 Published: Aug. 8, 2024, 4:04 p.m. 🔄 Last Modified: Oct. 1, 2025, 2:15 a.m.

6.5

CVSS3.1

CVE-2024-7477 - Avaya Aura System Manager SQL injection vulnerability

A SQL injection vulnerability was found which could allow a command line interface (CLI) user with administrative privileges to execute arbitrary queries against the Avaya Aura System Manager database.  Affected versions include 10.1.x.x and 10.2.x.x. Versions prior to 10.1 are end of manufacturer…

📅 Published: Aug. 8, 2024, 4:02 p.m. 🔄 Last Modified: Sept. 11, 2024, 3:03 p.m.

0.0

CVE-2024-7619 -

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

📅 Published: Aug. 8, 2024, 4:02 p.m. 🔄 Last Modified: Sept. 3, 2024, 6:15 p.m.

9.5

CVSS4.0

CVE-2024-7490 - Remote Code Execution in Advanced Software Framework DHCP server

Improper Input Validation vulnerability in Microchip Techology Advanced Software Framework example DHCP server can cause remote code execution through a buffer overflow. This vulnerability is associated with program files tinydhcpserver.C and program routines lwip_dhcp_find_option. This issue aff…

📅 Published: Aug. 8, 2024, 3:01 p.m. 🔄 Last Modified: Sept. 29, 2025, 9:40 p.m.

7.3

CVSS3.1

CVE-2024-42357 - Shopware vulnerable to blind SQL-injection in DAL aggregations

Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the Shopware application API contains a search functionality which enables users to search through information stored within their Shopware instance. The searches performed by this function can be aggregated using the pa…

📅 Published: Aug. 8, 2024, 2:55 p.m. 🔄 Last Modified: Aug. 12, 2024, 3:26 p.m.

8.3

CVSS3.1

CVE-2024-42356 - Shopware vulnerable to Server Side Template Injection in Twig using Context functions

Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the `context` variable is injected into almost any Twig Template and allows to access to current language, currency information. The context object allows also to switch for a short time the scope of the Context as a hel…

📅 Published: Aug. 8, 2024, 2:52 p.m. 🔄 Last Modified: Aug. 12, 2024, 3:34 p.m.

8.3

CVSS3.1

CVE-2024-42355 - Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tag

Shopware, an open ecommerce platform, has a new Twig Tag `sw_silent_feature_call` which silences deprecation messages while triggered in this tag. Prior to versions 6.6.5.1 and 6.5.8.13, it accepts as parameter a string the feature flag name to silence, but this parameter is not escaped properly an…

📅 Published: Aug. 8, 2024, 2:49 p.m. 🔄 Last Modified: Aug. 12, 2024, 3:40 p.m.
Total resulsts: 349182
Page 8914 of 34,919
« previous page » next page
Filters