6.9

CVSS4.0

CVE-2024-41685 - Cookie Without HTTPOnly Flag Set Vulnerability

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing HTTPOnly flag for the session cookies associated with the router's web management interface. An attacker with remote access could exploit this by intercepting transmission within an HTTP session on the vulnerable system.…

πŸ“… Published: July 26, 2024, 11:41 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:32 a.m.

6.9

CVSS4.0

CVE-2024-41684 - Cookie Without Secure Flag Set Vulnerability

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing secure flag for the session cookies associated with the router's web management interface. An attacker with remote access could exploit this by intercepting transmission within an HTTP session on the vulnerable system. …

πŸ“… Published: July 26, 2024, 11:34 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:32 a.m.

8.8

CVSS3.1

CVE-2024-7062 - Local Privilege Escalation in Nimble Commander <= v1.6.0, Build 4087

Nimble Commander suffers from a privilege escalation vulnerability due to the server (info.filesmanager.Files.PrivilegedIOHelperV2) performing improper/insufficient validation of a client’s authorization before executing an operation. Consequently, it is possible to execute system-level commands as…

πŸ“… Published: July 26, 2024, 11:26 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:50 a.m.

8.2

CVSS3.1

CVE-2024-35296 - Apache Traffic Server: Invalid Accept-Encoding can force forwarding requests

Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwarding requests. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4. Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.

πŸ“… Published: July 26, 2024, 9:11 a.m. πŸ”„ Last Modified: Nov. 3, 2025, 10:16 p.m.

6.5

CVSS3.1

CVE-2024-6490 - Master Slider – Responsive Touch Slider <= 3.9.10 - CSRF to slider deletion

During testing of the Master Slider WordPress plugin through 3.9.10, a CSRF vulnerability was found, which allows an unauthorized user to manipulate requests on behalf of the victim and thereby delete all of the sliders inside Master Slider WordPress plugin through 3.9.10.

πŸ“… Published: July 26, 2024, 6 a.m. πŸ”„ Last Modified: May 27, 2025, 4:32 p.m.

5.3

CVSS4.0

CVE-2024-7120 - Raisecom MSG1200/MSG2100E/MSG2200/MSG2300 Web Interface list_base_config.php os command injection

A vulnerability, which was classified as critical, was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. This affects an unknown part of the file list_base_config.php of the component Web Interface. The manipulation of the argument template leads to os command injection. It is possible…

πŸ“… Published: July 26, 2024, 5 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:50 a.m.

5.3

CVSS4.0

CVE-2024-7119 - MD-MAFUJUL-HASAN Online-Payroll-Management-System employee_viewmore.php sql injection

A vulnerability, which was classified as critical, has been found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. Affected by this issue is some unknown functionality of the file /employee_viewmore.php. The manipulation of the argument id leads to sql injection. The attack may …

πŸ“… Published: July 26, 2024, 4:31 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:50 a.m.

5.3

CVSS4.0

CVE-2024-7118 - MD-MAFUJUL-HASAN Online-Payroll-Management-System department_viewmore.php sql injection

A vulnerability classified as critical was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. Affected by this vulnerability is an unknown functionality of the file /department_viewmore.php. The manipulation of the argument id leads to sql injection. The attack can be launch…

πŸ“… Published: July 26, 2024, 4 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:50 a.m.

5.3

CVSS4.0

CVE-2024-7117 - MD-MAFUJUL-HASAN Online-Payroll-Management-System shift_viewmore.php sql injection

A vulnerability classified as critical has been found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. Affected is an unknown function of the file /shift_viewmore.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The e…

πŸ“… Published: July 26, 2024, 3:31 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:50 a.m.

5.3

CVSS4.0

CVE-2024-7116 - MD-MAFUJUL-HASAN Online-Payroll-Management-System branch_viewmore.php sql injection

A vulnerability was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. It has been rated as critical. This issue affects some unknown processing of the file /branch_viewmore.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely…

πŸ“… Published: July 26, 2024, 2:31 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:50 a.m.
Total resulsts: 349182
Page 9049 of 34,919
Β« previous page Β» next page
Filters