5.9

CVSS3.1

CVE-2024-38103 - Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

📅 Published: July 25, 2024, 9:33 p.m. 🔄 Last Modified: Dec. 9, 2025, 11:47 p.m.

5.4

CVSS3.1

CVE-2024-3938 -

The "reset password" login page accepted an HTML injection via URL parameters. This has already been rectified via patch, and as such it cannot be demonstrated via Demo site link. Those interested to see the vulnerability may spin up a http://localhost:8082/dotAdmin/#/public/login?resetEmailSent=…

📅 Published: July 25, 2024, 9:17 p.m. 🔄 Last Modified: Nov. 21, 2024, 9:30 a.m.

6.9

CVSS4.0

CVE-2024-7106 - Spina CMS media_folders cross-site request forgery

A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the publ…

📅 Published: July 25, 2024, 9 p.m. 🔄 Last Modified: Nov. 21, 2024, 9:50 a.m.

5.3

CVSS4.0

CVE-2024-7105 - ForIP Tecnologia Administração PABX Lista Ura Page detalheIdUra sql injection

A vulnerability classified as critical has been found in ForIP Tecnologia Administração PABX 1.x. Affected is an unknown function of the file /detalheIdUra of the component Lista Ura Page. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The …

📅 Published: July 25, 2024, 8:31 p.m. 🔄 Last Modified: Nov. 21, 2024, 9:50 a.m.

7.2

CVSS3.1

CVE-2024-41809 - OpenObserve Cross-site Scripting (XSS) vulnerability in `openobserve/web/src/views/MemberSubscripti…

OpenObserve is an open-source observability platform. Starting in version 0.4.4 and prior to version 0.10.0, OpenObserve contains a cross-site scripting vulnerability in line 32 of `openobserve/web/src/views/MemberSubscription.vue`. Version 0.10.0 sanitizes incoming html.

📅 Published: July 25, 2024, 8:22 p.m. 🔄 Last Modified: Nov. 21, 2024, 9:33 a.m.

8.8

CVSS3.1

CVE-2024-41808 - OpenObserve stored XSS vulnerability may lead to complete account takeover

The OpenObserve open-source observability platform provides the ability to filter logs in a dashboard by the values uploaded in a given log. However, all versions of the platform through 0.9.1 do not sanitize user input in the filter selection menu, which may result in complete account takeover. It…

📅 Published: July 25, 2024, 8:10 p.m. 🔄 Last Modified: Nov. 21, 2024, 9:33 a.m.

6.3

CVSS4.0

CVE-2024-6558 - HMS Industrial Networks Anybus-CompactCom 30 Cross-site Scripting

HMS Industrial Networks Anybus-CompactCom 30 products are vulnerable to a XSS attack caused by the lack of input sanitation checks. As a consequence, it is possible to insert HTML code into input fields and store the HTML code. The stored HTML code will be embedded in the page and executed by host…

📅 Published: July 25, 2024, 7:53 p.m. 🔄 Last Modified: Aug. 27, 2025, 8:43 p.m.

4.8

CVSS3.1

CVE-2024-29069 - snapd will follow archived symlinks when unpacking a filesystem

In snapd versions prior to 2.62, snapd failed to properly check the destination of symbolic links when extracting a snap. The snap format is a squashfs file-system image and so can contain symbolic links and other file types. Various file entries within the snap squashfs image (such as icons and d…

📅 Published: July 25, 2024, 7:39 p.m. 🔄 Last Modified: Nov. 21, 2024, 9:07 a.m.

5.8

CVSS3.1

CVE-2024-29068 - snapd non-regular file indefinite blocking read

In snapd versions prior to 2.62, snapd failed to properly check the file type when extracting a snap. The snap format is a squashfs file-system image and so can contain files that are non-regular files (such as pipes or sockets etc). Various file entries within the snap squashfs image (such as ico…

📅 Published: July 25, 2024, 7:28 p.m. 🔄 Last Modified: Nov. 21, 2024, 9:07 a.m.

4.5

CVSS3.1

CVE-2024-40873 - XSS in Secure Access administrative console

There is a cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.07. Attackers with system administrator permissions can interfere with another system administrator’s use of the publishing UI when the administrators are editing …

📅 Published: July 25, 2024, 5:19 p.m. 🔄 Last Modified: Nov. 21, 2024, 9:31 a.m.
Total resulsts: 349182
Page 9053 of 34,919
« previous page » next page
Filters