8.8

CVSS3.1

CVE-2024-6144 - Actiontec WCB6200Q Multipart Boundary Stack-based Buffer Overflow Remote Code Execution Vulnerabili…

Actiontec WCB6200Q Multipart Boundary Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Actiontec WCB6200Q routers. Authentication is not required to exploit this vulnerability…

📅 Published: June 18, 2024, 11:38 p.m. 🔄 Last Modified: Nov. 21, 2024, 9:49 a.m.

8.8

CVSS3.1

CVE-2024-6143 - Actiontec WCB6200Q uh_tcp_recv_header Buffer Overflow Remote Code Execution Vulnerability

Actiontec WCB6200Q uh_tcp_recv_header Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Actiontec WCB6200Q routers. Authentication is not required to exploit this vulnerability. The speci…

📅 Published: June 18, 2024, 11:38 p.m. 🔄 Last Modified: Nov. 21, 2024, 9:49 a.m.

8.8

CVSS3.1

CVE-2024-6142 - Actiontec WCB6200Q uh_tcp_recv_content Buffer Overflow Remote Code Execution Vulnerability

Actiontec WCB6200Q uh_tcp_recv_content Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Actiontec WCB6200Q routers. Authentication is not required to exploit this vulnerability. The spec…

📅 Published: June 18, 2024, 11:38 p.m. 🔄 Last Modified: Nov. 21, 2024, 9:49 a.m.

6.4

CVSS3.1

CVE-2024-5970 - MaxGalleria <= 6.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via maxgallery_thum…

The MaxGalleria plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's maxgallery_thumb shortcode in all versions up to, and including, 6.4.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated …

📅 Published: June 18, 2024, 9:36 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS4.0

CVE-2024-6129 - spa-cartcms Username login observable behavioral discrepancy

A vulnerability, which was classified as problematic, was found in spa-cartcms 1.9.0.6. Affected is an unknown function of the file /login of the component Username Handler. The manipulation of the argument email leads to observable behavioral discrepancy. It is possible to launch the attack remote…

📅 Published: June 18, 2024, 9 p.m. 🔄 Last Modified: Nov. 21, 2024, 9:49 a.m.

6.9

CVSS4.0

CVE-2024-6128 - spa-cartcms Checkout Page checkout behavioral workflow

A vulnerability, which was classified as problematic, has been found in spa-cartcms 1.9.0.6. This issue affects some unknown processing of the file /checkout of the component Checkout Page. The manipulation of the argument quantity with the input -10 leads to enforcement of behavioral workflow. The…

📅 Published: June 18, 2024, 9 p.m. 🔄 Last Modified: Nov. 21, 2024, 9:49 a.m.

5.4

CVSS3.1

CVE-2024-38277 - moodle: QR login key and auto-login key for the Moodle mobile app should be generated as separate k…

A unique key should be generated for a user's QR login key and their auto-login key, so the same key cannot be used interchangeably between the two.

📅 Published: June 18, 2024, 7:49 p.m. 🔄 Last Modified: Aug. 7, 2025, 5:24 p.m.

8.8

CVSS3.1

CVE-2024-38276 - moodle: CSRF risks due to misuse of confirm_sesskey

Incorrect CSRF token checks resulted in multiple CSRF risks.

📅 Published: June 18, 2024, 7:49 p.m. 🔄 Last Modified: March 26, 2025, 2:15 p.m.

7.5

CVSS3.1

CVE-2024-38275 - moodle: HTTP authorization header is preserved between "emulated redirects"

The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.

📅 Published: June 18, 2024, 7:49 p.m. 🔄 Last Modified: April 30, 2025, 11:35 p.m.

6.1

CVSS3.1

CVE-2024-38274 - moodle: stored XSS via calendar's event title when deleting the event

Insufficient escaping of calendar event titles resulted in a stored XSS risk in the event deletion prompt.

📅 Published: June 18, 2024, 7:49 p.m. 🔄 Last Modified: Aug. 7, 2025, 5:23 p.m.
Total resulsts: 346617
Page 9155 of 34,662
« previous page » next page
Filters