5.4

CVSS3.1

CVE-2024-5759 - Improper privilege management

An improper privilege management vulnerability exists in Tenable Security Center where an authenticated, remote attacker could view unauthorized objects and launch scans without having the required privileges

πŸ“… Published: June 12, 2024, 4 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:48 a.m.

6.9

CVSS4.0

CVE-2024-5897 - SourceCodester Employee and Visitor Gate Pass Logging System cross site scripting

A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=log_visitor. The manipulation of the argument name leads to cross site scrip…

πŸ“… Published: June 12, 2024, 4 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:48 a.m.

3.5

CVSS3.1

CVE-2024-1891 - Stored Cross Site Scripting

A stored cross site scripting vulnerability exists in Tenable Security Center where an authenticated, remote attacker could inject HTML code into a web application scan result page.

πŸ“… Published: June 12, 2024, 3:56 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 8:51 a.m.

6.9

CVSS4.0

CVE-2024-5896 - SourceCodester Employee and Visitor Gate Pass Logging System save_users sql injection

A vulnerability, which was classified as critical, was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. Affected is the function save_users of the file /classes/Users.php?f=save. The manipulation of the argument id leads to sql injection. It is possible to launch the attac…

πŸ“… Published: June 12, 2024, 3:31 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:48 a.m.

8.1

CVSS3.1

CVE-2024-37300 - Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0

OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. JupyterHub < 5.0, when used with `GlobusOAuthenticator`, could be configured to allow all users from a particular institution only. This worked fine prior to JupyterHub 5.0, because `allow_al…

πŸ“… Published: June 12, 2024, 3:20 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-37297 - WooCommerce has a Cross-Site Scripting Vulnerability in checkout & registration forms

WooCommerce is an open-source e-commerce platform built on WordPress. A vulnerability introduced in WooCommerce 8.8 allows for cross-site scripting. A bad actor can manipulate a link to include malicious HTML & JavaScript content. While the content is not saved to the database, the links may be sen…

πŸ“… Published: June 12, 2024, 3:05 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:23 a.m.

7.8

CVSS3.1

CVE-2024-28964 -

Dell Common Event Enabler, version 8.9.10.0 and prior, contain an insecure deserialization vulnerability in CAVATools. A local unauthenticated attacker could potentially exploit this vulnerability, leading to arbitrary code execution in the context of the logged in user. Exploitation of this issue …

πŸ“… Published: June 12, 2024, 3:02 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:07 a.m.

6.2

CVSS3.1

CVE-2024-2300 - HP Advance Mobile Application – Potential Information Disclosure

HP Advance Mobile Applications for iOS and Android are potentially vulnerable to information disclosure when using an outdated version of the application via mobile devices.

πŸ“… Published: June 12, 2024, 3 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-5895 - SourceCodester Employee and Visitor Gate Pass Logging System delete_users sql injection

A vulnerability, which was classified as critical, has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. This issue affects the function delete_users of the file /classes/Users.php?f=delete. The manipulation of the argument id leads to sql injection. The attack may be …

πŸ“… Published: June 12, 2024, 3 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:48 a.m.

6.9

CVSS4.0

CVE-2024-5894 - SourceCodester Online Eyewear Shop manage_product.php sql injection

A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. This vulnerability affects unknown code of the file manage_product.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the…

πŸ“… Published: June 12, 2024, 3 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:48 a.m.
Total resulsts: 347056
Page 9270 of 34,706
Β« previous page Β» next page
Filters