8.8

CVSS3.1

CVE-2024-41667 - OpenAM FreeMarker template injection

OpenAM is an open access management solution. In versions 15.0.3 and prior, the `getCustomLoginUrlTemplate` method in RealmOAuth2ProviderSettings.java is vulnerable to template injection due to its usage of user input. Although the developer intended to implement a custom URL for handling login to …

πŸ“… Published: July 24, 2024, 5:29 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.4

CVSS3.1

CVE-2024-37533 - IBM InfoSphere Information Server information disclosure

IBM InfoSphere Information Server 11.7 could disclose sensitive user information to another user with physical access to the machine. IBM X-Force ID: 294727.

πŸ“… Published: July 24, 2024, 5:05 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:24 a.m.

7.1

CVSS3.1

CVE-2024-41091 - tun: add missing verification for short frame

In the Linux kernel, the following vulnerability has been resolved: tun: add missing verification for short frame The cited commit missed to check against the validity of the frame length in the tun_xdp_one() path, which could cause a corrupted skb to be sent downstack. Even before the skb is tra…

πŸ“… Published: July 24, 2024, 5 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 10:17 p.m.

7.1

CVSS3.1

CVE-2024-41090 - tap: add missing verification for short frame

In the Linux kernel, the following vulnerability has been resolved: tap: add missing verification for short frame The cited commit missed to check against the validity of the frame length in the tap_get_user_xdp() path, which could cause a corrupted skb to be sent downstack. Even before the skb i…

πŸ“… Published: July 24, 2024, 5 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 10:17 p.m.

8.6

CVSS3.1

CVE-2024-41662 - VNote vulnerable to Markdown XSS, which leads to RCE

VNote is a note-taking platform. A Cross-Site Scripting (XSS) vulnerability has been identified in the Markdown rendering functionality of versions 3.18.1 and prior of the VNote note-taking application. This vulnerability allows the injection and execution of arbitrary JavaScript code through which…

πŸ“… Published: July 24, 2024, 4:55 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:32 a.m.

5.3

CVSS4.0

CVE-2024-7069 - SourceCodester Employee and Visitor Gate Pass Logging System sql injection

A vulnerability, which was classified as critical, has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. This issue affects some unknown processing of the file /employee_gatepass/classes/Master.php?f=delete_department. The manipulation of the argument id leads to sql i…

πŸ“… Published: July 24, 2024, 3:31 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:50 a.m.

6.1

CVSS3.1

CVE-2024-22444 -

A vulnerability within the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a vic…

πŸ“… Published: July 24, 2024, 3:17 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 8:56 a.m.

7.2

CVSS3.1

CVE-2024-22443 -

A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the under…

πŸ“… Published: July 24, 2024, 3:08 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 8:56 a.m.

5.3

CVSS4.0

CVE-2024-7068 - SourceCodester Insurance Management System update_sub_category cross site scripting

A vulnerability classified as problematic has been found in SourceCodester Insurance Management System 1.0. This affects an unknown part of the file /Script/admin/core/update_sub_category. The manipulation of the argument name leads to cross site scripting. It is possible to initiate the attack rem…

πŸ“… Published: July 24, 2024, 3 p.m. πŸ”„ Last Modified: April 22, 2025, 4:02 p.m.

8.1

CVSS3.1

CVE-2024-41914 -

A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary s…

πŸ“… Published: July 24, 2024, 2:57 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:33 a.m.
Total resulsts: 349182
Page 9059 of 34,919
Β« previous page Β» next page
Filters