6.8

CVSS3.1

CVE-2024-38302 -

Dell Data Lakehouse, version(s) 1.0.0.0, contain(s) a Missing Encryption of Sensitive Data vulnerability in the DDAE (Starburst). A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure.

๐Ÿ“… Published: July 18, 2024, 3:51 p.m. ๐Ÿ”„ Last Modified: Feb. 4, 2025, 5:24 p.m.

4.9

CVSS3.1

CVE-2024-30473 -

Dell ECS, versions prior to 3.8.1, contain a privilege elevation vulnerability in user management. A remote high privileged attacker could potentially exploit this vulnerability, gaining access to unauthorized end points.

๐Ÿ“… Published: July 18, 2024, 3:39 p.m. ๐Ÿ”„ Last Modified: Feb. 4, 2025, 5:22 p.m.

10

CVSS3.1

CVE-2024-39911 - 1Panel SQL injection

1Panel is a web-based linux server management control panel. 1Panel contains an unspecified sql injection via User-Agent handling. This issue has been addressed in version 1.10.12-lts. Users are advised to upgrade. There are no known workarounds for this vulnerability.

๐Ÿ“… Published: July 18, 2024, 3:35 p.m. ๐Ÿ”„ Last Modified: Feb. 13, 2025, 5:53 p.m.

9.8

CVSS3.1

CVE-2024-39907 - a sqlinjection in 1Panel

1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs. These sql injections have been resolved in version 1.10.12-tls. Users are advised to uโ€ฆ

๐Ÿ“… Published: July 18, 2024, 3:31 p.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:28 a.m.

7.8

CVSS3.0

CVE-2024-34013 -

Local privilege escalation due to OS command injection vulnerability. The following products are affected: Acronis True Image (macOS) before build 41396, Acronis True Image OEM (macOS) before build 42571.

๐Ÿ“… Published: July 18, 2024, 1:36 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-31143 - double unlock in x86 guest IRQ handling

An optional feature of PCI MSI called "Multiple Message" allows a device to use multiple consecutive interrupt vectors. Unlike for MSI-X, the setting up of these consecutive vectors needs to happen all in one go. In this handling an error path could be taken in different situations, with or withoโ€ฆ

๐Ÿ“… Published: July 18, 2024, 1:31 p.m. ๐Ÿ”„ Last Modified: Jan. 14, 2026, 4:31 p.m.

8.8

CVSS3.1

CVE-2024-29178 - Apache StreamPark: FreeMarker SSTI RCE Vulnerability

On versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code Execution on the server,ย The attacker must successfully log into the system to launch an attack, so this is a moderate-impact vulnerability. Mitigation: all users should upgrade to 2.1.4

๐Ÿ“… Published: July 18, 2024, 11:15 a.m. ๐Ÿ”„ Last Modified: Feb. 13, 2025, 6:17 p.m.

4.3

CVSS3.1

CVE-2024-6504 - Rapid7 InsightVM Protection Mechanism Failure

Rapid7 InsightVM Console versions below 6.6.260 suffer from a protection mechanism failure whereby an attacker with network access to the InsightVM Console can cause it to overload or crash by sending repeated invalid REST requests in a short timeframe, to the Console's port 443 causing the consoleโ€ฆ

๐Ÿ“… Published: July 18, 2024, 9:32 a.m. ๐Ÿ”„ Last Modified: Sept. 11, 2025, 2:13 p.m.

5.3

CVSS3.1

CVE-2024-40725 - Apache HTTP Server: source code disclosure with handlers configured via AddType

A partial fix forย  CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local conteโ€ฆ

๐Ÿ“… Published: July 18, 2024, 9:32 a.m. ๐Ÿ”„ Last Modified: March 14, 2025, 6:15 p.m.

6.4

CVSS3.1

CVE-2024-5555 - Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrโ€ฆ

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the โ€˜social-link-titleโ€™ parameter in all versions up to, and including, 5.6.5 due to insufficient input sanitization and โ€ฆ

๐Ÿ“… Published: July 18, 2024, 8:33 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 7:21 p.m.
Total resulsts: 349182
Page 9108 of 34,919
ยซ previous page ยป next page
Filters