7.9

CVSS3.1

CVE-2024-21980 - kernel: hw:amd: Guest Memory Vulnerability in SNP

Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a guest's memory or UMC seed resulting in loss of confidentiality and integrity.

πŸ“… Published: Aug. 5, 2024, midnight πŸ”„ Last Modified: Nov. 26, 2024, 7:13 p.m.

6.1

CVSS3.1

CVE-2024-41380 -

microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\tags\add_tagging_tagged.php.

πŸ“… Published: Aug. 5, 2024, midnight πŸ”„ Last Modified: July 10, 2025, 3:48 p.m.

8.8

CVSS3.1

CVE-2024-41376 -

dzzoffice 2.02.1 is vulnerable to Directory Traversal via user/space/about.php.

πŸ“… Published: Aug. 5, 2024, midnight πŸ”„ Last Modified: Nov. 20, 2025, 4:35 p.m.

7.8

CVSS3.1

CVE-2024-6472 - Ability to trust not validated macro signatures removed in high security mode

Certificate Validation user interface in LibreOffice allows potential vulnerability. Signed macros are scripts that have been digitally signed by the developer using a cryptographic signature. When a document with a signed macro is opened a warning is displayed by LibreOffice before the macro…

πŸ“… Published: Aug. 5, 2024, midnight πŸ”„ Last Modified: Dec. 10, 2025, 7:22 p.m.

7.5

CVSS3.1

CVE-2024-40530 -

A vulnerability in Pantera CRM versions 401.152 and 402.072 allows unauthorized attackers to bypass IP-based access controls by manipulating the X-Forwarded-For header.

πŸ“… Published: Aug. 5, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-40498 -

SQL Injection vulnerability in PuneethReddyHC Online Shopping sysstem advanced v.1.0 allows an attacker to execute arbitrary code via the register.php

πŸ“… Published: Aug. 5, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-40531 -

A mass assignment vulnerability exists in Pantera CRM versions 401.152 and 402.072. This flaw allows authenticated users to modify any user attribute, including roles, by injecting additional parameters via profile management functions.

πŸ“… Published: Aug. 5, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS3.1

CVE-2024-42008 -

A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a malicious e-mail attachment served with a dangerous Content-Type header.

πŸ“… Published: Aug. 5, 2024, midnight πŸ”„ Last Modified: March 13, 2025, 4:15 p.m.

6

CVSS3.1

CVE-2024-21978 - linux-firmware: hw:amd: Improper input validation in SEV-SNP

Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially leading to data leakage or data corruption.

πŸ“… Published: Aug. 5, 2024, midnight πŸ”„ Last Modified: Nov. 26, 2024, 7:13 p.m.

6.1

CVSS3.1

CVE-2024-41381 -

microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\settings\admin.php.

πŸ“… Published: Aug. 5, 2024, midnight πŸ”„ Last Modified: July 10, 2025, 3:48 p.m.
Total resulsts: 349182
Page 8959 of 34,919
Β« previous page Β» next page
Filters