6.9

CVSS4.0

CVE-2024-7360 - SourceCodester Tracking Monitoring Management System ajax.php cross-site request forgery

A vulnerability classified as problematic has been found in SourceCodester Tracking Monitoring Management System 1.0. This affects an unknown part of the file /ajax.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclo…

📅 Published: Aug. 1, 2024, 5:31 p.m. 🔄 Last Modified: Aug. 9, 2024, 2:24 p.m.

2.7

CVSS3.1

CVE-2024-23600 - PingIDM Query Filter Vulnerability

Improper Input Validation of query search results for private field data in PingIDM (Query Filter module) allows for a potentially efficient brute forcing approach leading to information disclosure.

📅 Published: Aug. 1, 2024, 4:55 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.7

CVSS3.1

CVE-2024-7211 - The Duende Identity Server based component in 1E Platform may allow URL redirections to untrusted w…

The 1E Platform's component utilized the third-party Duende Identity Server, which suffered from an open redirect vulnerability, permitting an attacker to control the redirection path of end users. Note: 1E Platform's component utilizing the third-party Duende Identity Server has been updated with…

📅 Published: Aug. 1, 2024, 4:49 p.m. 🔄 Last Modified: June 18, 2025, 6:41 p.m.

5.3

CVSS4.0

CVE-2024-7359 - SourceCodester Tracking Monitoring Management System ajax.php cross site scripting

A vulnerability was found in SourceCodester Tracking Monitoring Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /ajax.php?action=save_establishment. The manipulation of the argument name leads to cross site scripting. The att…

📅 Published: Aug. 1, 2024, 4:31 p.m. 🔄 Last Modified: Aug. 9, 2024, 2:23 p.m.

4.6

CVSS3.1

CVE-2024-41962 - Bostr Improper Authorization

Bostr is an nostr relay aggregator proxy that acts like a regular nostr relay. bostr let everyone in even having authorized_keys being set when noscraper is set to true. This vulnerability is fixed in 3.0.10.

📅 Published: Aug. 1, 2024, 4:30 p.m. 🔄 Last Modified: Aug. 16, 2024, 4:34 p.m.

8.1

CVSS3.1

CVE-2024-6873 - Specially crafted request could caused undefined behaviour which may lead to Remote Code Execution.

It is possible to crash or redirect the execution flow of the ClickHouse server process from an unauthenticated vector by sending a specially crafted request to the ClickHouse server native interface. This redirection is limited to what is available within a 256-byte range of memory at the time of …

📅 Published: Aug. 1, 2024, 3:57 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-6040 - Missing client_id in parisneo/lollms-webui

In parisneo/lollms-webui version v9.8, the lollms_binding_infos is missing the client_id parameter, which leads to multiple security vulnerabilities. Specifically, the endpoints /reload_binding, /install_binding, /reinstall_binding, /unInstall_binding, /set_active_binding_settings, and /update_bind…

📅 Published: Aug. 1, 2024, 3:32 p.m. 🔄 Last Modified: Oct. 15, 2025, 1:15 p.m.

7.3

CVSS4.0

CVE-2024-6242 - Rockwell Automation Chassis Restrictions Bypass Vulnerability in Select Logix Devices

A vulnerability exists in Rockwell Automation affected products that allows a threat actor to bypass the Trusted® Slot feature in a ControlLogix® controller. If exploited on any affected module in a 1756 chassis, a threat actor could potentially execute CIP commands that modify user projects and/or…

📅 Published: Aug. 1, 2024, 3:15 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.2

CVSS3.1

CVE-2024-41961 - Elektra vulnerable to remote code execution in universal search

Elektra is an opinionated Openstack Dashboard for Operators and Consumers of Openstack Services. A code injection vulnerability was found in the live search functionality of the Ruby on Rails based Elektra web application. An authenticated user can craft a search term containing Ruby code, which la…

📅 Published: Aug. 1, 2024, 2:33 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

2.7

CVSS3.1

CVE-2024-41926 - Malicious remote can claim that a user was synced from another remote

Mattermost versions 9.9.x <= 9.9.0 and 9.5.x <= 9.5.6 fail to validate the source of sync messages and only allow the correct remote IDs, which allows a malicious remote to set arbitrary RemoteId values for synced users and therefore claim that a user was synced from another remote.

📅 Published: Aug. 1, 2024, 2:05 p.m. 🔄 Last Modified: Sept. 4, 2024, 4:55 p.m.
Total resulsts: 349182
Page 8977 of 34,919
« previous page » next page
Filters