7

CVSS4.0

CVE-2024-3640 - Rockwell Automation FactoryTalk® Remote Access™ has Unquoted Executables

An unquoted executable path exists in the Rockwell Automation FactoryTalk® Remote Access™ possibly resulting in remote code execution if exploited. While running the FTRA installer package, the executable path is not properly quoted, which could allow a threat actor to enter a malicious executable …

📅 Published: May 16, 2024, 3:25 p.m. 🔄 Last Modified: Nov. 21, 2024, 9:30 a.m.

9.1

CVSS3.1

CVE-2024-35187 - Stalwart Mail Server has privilege escalation by design

Stalwart Mail Server is an open-source mail server. Prior to version 0.8.0, attackers who achieved Arbitrary Code Execution as the stalwart-mail user (including web interface admins) can gain complete root access to the system. Usually, system services are run as a separate user (not as root) to is…

📅 Published: May 16, 2024, 3:16 p.m. 🔄 Last Modified: Nov. 21, 2024, 9:19 a.m.

5.9

CVSS3.1

CVE-2024-34273 -

njwt up to v0.4.0 was discovered to contain a prototype pollution in the Parser.prototype.parse method.

📅 Published: May 16, 2024, 3:16 p.m. 🔄 Last Modified: Feb. 13, 2025, 3:53 p.m.

5.3

CVSS3.1

CVE-2024-35185 - Denial of service of Minder Server with attacker-controlled REST endpoint

Minder is a software supply chain security platform. Prior to version 0.0.49, the Minder REST ingester is vulnerable to a denial of service attack via an attacker-controlled REST endpoint that can crash the Minder server. The REST ingester allows users to interact with REST endpoints to fetch data …

📅 Published: May 16, 2024, 3:15 p.m. 🔄 Last Modified: Nov. 21, 2024, 9:19 a.m.

8.8

CVSS4.0

CVE-2024-4609 - Rockwell Automation Datalog Function within in FactoryTalk® View SE contains SQL Injection Vulnerab…

A vulnerability exists in the Rockwell Automation FactoryTalk® View SE Datalog function that could allow a threat actor to inject a malicious SQL statement if the SQL database has no authentication in place or if legitimate credentials were stolen. If exploited, the attack could result in informati…

📅 Published: May 16, 2024, 3:13 p.m. 🔄 Last Modified: Jan. 30, 2025, 3:50 p.m.

0.0

CVE-2024-5007 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

📅 Published: May 16, 2024, 3:02 p.m. 🔄 Last Modified: July 5, 2025, 11:15 p.m.

5.4

CVSS3.1

CVE-2024-34957 -

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/sysImages_deal.php?mudi=infoSet.

📅 Published: May 16, 2024, 2:34 p.m. 🔄 Last Modified: April 15, 2025, 5:03 p.m.

6.5

CVSS3.1

CVE-2024-34958 -

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/banner_deal.php?mudi=add

📅 Published: May 16, 2024, 2:32 p.m. 🔄 Last Modified: April 15, 2025, 5:03 p.m.

3.8

CVSS3.1

CVE-2024-35039 -

idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/tplSys_deal.php?mudi=area.

📅 Published: May 16, 2024, 2:29 p.m. 🔄 Last Modified: April 15, 2025, 5:03 p.m.

6.1

CVSS3.1

CVE-2024-34582 -

Sunhillo SureLine through 8.10.0 on RICI 5000 devices allows cgi/usrPasswd.cgi userid_change XSS within the Forgot Password feature.

📅 Published: May 16, 2024, 2:18 p.m. 🔄 Last Modified: Feb. 13, 2025, 3:53 p.m.
Total resulsts: 343054
Page 9218 of 34,306
« previous page » next page
Filters