6.8

CVSS3.1

CVE-2024-28772 - IBM Security Directory Integrator cross-site scripting

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disc…

📅 Published: July 25, 2024, 5:18 p.m. 🔄 Last Modified: Nov. 21, 2024, 9:06 a.m.

5.3

CVSS3.1

CVE-2022-32759 - IBM Security Directory Server information disclosure

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 uses insufficient session expiration which could allow an unauthorized user to obtain sensitive information. IBM X-Force ID: 228565.

📅 Published: July 25, 2024, 5:11 p.m. 🔄 Last Modified: Nov. 21, 2024, 7:06 a.m.

8.4

CVSS3.1

CVE-2024-40872 - Elevation of privilege in Absolute Secure Access clients and servers

There is an elevation of privilege vulnerability in server and client components of Absolute Secure Access prior to version 13.07. Attackers with local access and valid desktop user credentials can elevate their privilege to system level by passing invalid address data to the vulnerable component. …

📅 Published: July 25, 2024, 5 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.7

CVSS3.1

CVE-2024-41801 - OpenProject packaged installation has Open Redirect Vulnerability in Sign-In in default configurati…

OpenProject is open source project management software. Prior to version 14.3.0, using a forged HOST header in the default configuration of packaged installations and using the "Login required" setting, an attacker could redirect to a remote host to initiate a phishing attack against an OpenProject…

📅 Published: July 25, 2024, 4:50 p.m. 🔄 Last Modified: Nov. 21, 2024, 9:33 a.m.

8.7

CVSS4.0

CVE-2024-7007 - Authentication Bypass Using an Alternate Path or Channel in Positron Broadcast Signal Processor TRA…

Positron Broadcast Signal Processor TRA7005 v1.20 is vulnerable to an authentication bypass exploit that could allow an attacker to have unauthorized access to protected areas of the application.

📅 Published: July 25, 2024, 4:42 p.m. 🔄 Last Modified: Nov. 21, 2024, 9:50 a.m.

4.8

CVSS3.1

CVE-2024-41800 - Craft CMS Allows TOTP Token To Stay Valid After Use

Craft is a content management system (CMS). Craft CMS 5 allows reuse of TOTP tokens multiple times within the validity period. An attacker is able to re-submit a valid TOTP token to establish an authenticated session. This requires that the attacker has knowledge of the victim's credentials. This h…

📅 Published: July 25, 2024, 4:12 p.m. 🔄 Last Modified: Nov. 21, 2024, 9:33 a.m.

6.9

CVSS4.0

CVE-2024-7101 - ForIP Tecnologia Administração PABX Authentication Form login sql injection

A vulnerability, which was classified as critical, has been found in ForIP Tecnologia Administração PABX 1.x. This issue affects some unknown processing of the file /login of the component Authentication Form. The manipulation of the argument usuario leads to sql injection. The attack may be initia…

📅 Published: July 25, 2024, 4 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-41806 - Open edX Platform's instructor upload CSV for cohort creation not Private by Default

The Open edX Platform is a learning management platform. Instructors can upload csv files containing learner information to create cohorts in the instructor dashboard. These files are uploaded using the django default storage. With certain storage backends, uploads may become publicly available whe…

📅 Published: July 25, 2024, 2:34 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS3.1

CVE-2024-36111 - KubePi's JWT token validation has a defect

KubePi is a K8s panel. Starting in version 1.6.3 and prior to version 1.8.0, there is a defect in the KubePi JWT token verification. The JWT key in the default configuration file is empty. Although a random 32-bit string will be generated to overwrite the key in the configuration file when the key …

📅 Published: July 25, 2024, 1:26 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.4

CVSS3.1

CVE-2024-39672 -

Memory request logic vulnerability in the memory module. Impact: Successful exploitation of this vulnerability will affect integrity and availability.

📅 Published: July 25, 2024, 11:56 a.m. 🔄 Last Modified: Nov. 21, 2024, 9:28 a.m.
Total resulsts: 349182
Page 9054 of 34,919
« previous page » next page
Filters