5.4

CVSS3.1

CVE-2024-39310 - WordPress Basil Theme Authenticated (Contributor+) Persistent Cross-Site Scripting Vulnerability

The Basil recipe theme for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the `post_title` parameter in versions up to, and including, 2.0.4 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with contributor-level acc…

πŸ“… Published: July 1, 2024, 9:19 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-39309 - ZDI-CAN-23894: Parse Server literalizeRegexPart SQL Injection Authentication Bypass Vulnerability

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A vulnerability in versions prior to 6.5.7 and 7.1.0 allows SQL injection when Parse Server is configured to use the PostgreSQL database. The algorithm to detect SQL injection has been improved i…

πŸ“… Published: July 1, 2024, 9:15 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-39305 - Envoy Proxy use after free when route hash policy is configured with cookie attributes

Envoy is a cloud-native, open source edge and service proxy. Prior to versions 1.30.4, 1.29.7, 1.28.5, and 1.27.7. Envoy references already freed memory when route hash policy is configured with cookie attributes. Note that this vulnerability has been fixed in the open as the effect would be immedi…

πŸ“… Published: July 1, 2024, 9:10 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 8:30 p.m.

9.3

CVSS3.1

CVE-2024-38368 - Trunk's 'Claim your pod' could be used to obtain un-used pods

trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. A vulnerability affected older pods which migrated from the pre-2014 pull request workflow to trunk. If the pods had never been claimed then it was still possible to do so. It was also possible to have all owner…

πŸ“… Published: July 1, 2024, 9:05 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:25 a.m.

9.1

CVSS3.1

CVE-2024-28200 - N-central Authentication Bypass

The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central prior to 2024.2. This vulnerability was discovered through internal N-central source code review and N-able has not observed any exploitation in the w…

πŸ“… Published: July 1, 2024, 8:49 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:06 a.m.

8.2

CVSS3.1

CVE-2024-38367 - CoacoaPods trunk sessions verification step could be manipulated for owner session hijacking

trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. Prior to commit d4fa66f49cedab449af9a56a21ab40697b9f7b97, the trunk sessions verification step could be manipulated for owner session hijacking Compromising a victim’s session will result in a full takeover of t…

πŸ“… Published: July 1, 2024, 8:48 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:25 a.m.

9.1

CVSS3.1

CVE-2024-5322 - N-central Authentication Bypass via Session Rebinding

The N-central server is vulnerable to session rebinding of already authenticated users when using Entra SSO, which can lead to authentication bypass. This vulnerability is present in all Entra-supported deployments of N-central prior to 2024.3.

πŸ“… Published: July 1, 2024, 8:46 p.m. πŸ”„ Last Modified: Sept. 8, 2025, 4:17 p.m.

10

CVSS3.1

CVE-2024-38366 - CoacoaPods trunk RCE in email verification system rfc-822

trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. The part of trunk which verifies whether a user has a real email address on signup used a rfc-822 library which executes a shell command to validate the email domain MX records validity. It works via an DNS MX. …

πŸ“… Published: July 1, 2024, 8:42 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:25 a.m.

4.4

CVSS3.1

CVE-2024-39303 - Weblate vulnerabler to improper sanitization of project backups

Weblate is a web based localization tool. Prior to version 5.6.2, Weblate didn't correctly validate filenames when restoring project backup. It may be possible to gain unauthorized access to files on the server using a crafted ZIP file. This issue has been addressed in Weblate 5.6.2. As a workaroun…

πŸ“… Published: July 1, 2024, 6:46 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:27 a.m.

10

CVSS3.1

CVE-2024-38513 - Fiber Session Middleware Token Injection Vulnerability

Fiber is an Express-inspired web framework written in Go A vulnerability present in versions prior to 2.52.5 is a session middleware issue in GoFiber versions 2 and above. This vulnerability allows users to supply their own session_id value, resulting in the creation of a session with that key. If …

πŸ“… Published: July 1, 2024, 6:31 p.m. πŸ”„ Last Modified: Oct. 2, 2025, 1:55 p.m.
Total resulsts: 347734
Page 9143 of 34,774
Β« previous page Β» next page
Filters