10

CVSS4.0

CVE-2024-1839 -

Intrado 911 Emergency Gateway login form is vulnerable to an unauthenticated blind time-based SQL injection, which may allow an unauthenticated remote attacker to execute malicious code, exfiltrate data, or manipulate the database.

πŸ“… Published: June 26, 2024, 8:23 p.m. πŸ”„ Last Modified: Sept. 26, 2025, 2:31 p.m.

5.4

CVSS3.1

CVE-2024-38527 - Cross-site Scripting in ZenUML

ZenUML is JavaScript-based diagramming tool that requires no server, using Markdown-inspired text definitions and a renderer to create and modify sequence diagrams. Markdown-based comments in the ZenUML diagram syntax are susceptible to Cross-site Scripting (XSS). The comment feature allows the use…

πŸ“… Published: June 26, 2024, 7:33 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-38520 - SoftEther VPN with L2TP - 2.75x Amplification

SoftEtherVPN is a an open-source cross-platform multi-protocol VPN Program. When SoftEtherVPN is deployed with L2TP enabled on a device, it introduces the possibility of the host being used for amplification/reflection traffic generation because it will respond to every packet with two response pac…

πŸ“… Published: June 26, 2024, 6:59 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-38375 - @fastly/js-compute use-after-free in some host call implementations

@fastly/js-compute is a JavaScript SDK and runtime for building Fastly Compute applications. The implementation of several functions were determined to include a use-after-free bug. This bug could allow for unintended data loss if the result of the preceding functions were sent anywhere else, and o…

πŸ“… Published: June 26, 2024, 6:46 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2024-6354 -

Improper access control in PAM dashboard in Devolutions Remote Desktop Manager 2024.2.11 and earlier on Windows allows an authenticated user to bypass the execute permission via the use of the PAM dashboard.

πŸ“… Published: June 26, 2024, 4:20 p.m. πŸ”„ Last Modified: March 28, 2025, 4:19 p.m.

3.1

CVSS3.1

CVE-2024-25637 - Reflected XSS via X-October-Request-Handler Header

October is a self-hosted CMS platform based on the Laravel PHP Framework. The X-October-Request-Handler Header does not sanitize the AJAX handler name and allows unescaped HTML to be reflected back. There is no impact since this vulnerability cannot be exploited through normal browser interactions.…

πŸ“… Published: June 26, 2024, 3:55 p.m. πŸ”„ Last Modified: Sept. 29, 2025, 2:09 p.m.

7.1

CVSS4.0

CVE-2024-38272 - Auth Bypass in Quick Share

There exists a vulnerability in Quick Share/Nearby, where an attacker can bypass the accept file dialog on Quick Share Windows.Β Normally in Quick Share Windows app we can't send a file without the user accept from the receiving device if the visibility is set to everyone mode or contacts mode.Β We r…

πŸ“… Published: June 26, 2024, 3:19 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:25 a.m.

5.9

CVSS4.0

CVE-2024-38271 - Denial of Service in Quick Share

There exists a vulnerability in Quick Share/Nearby, where an attacker can force a victim to stay connected to a temporary hotspot created for the sharing. As part of the sequence of packets in a Quick Share connection over Bluetooth, the attacker forces the victim to connect to the attacker’s WiFi …

πŸ“… Published: June 26, 2024, 3:19 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:25 a.m.

6.1

CVSS3.1

CVE-2024-4604 - Open Redirect in Magarsus Consultancy's SSO

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Magarsus Consultancy SSO (Single Sign On) allows Manipulating Hidden Fields.This issue affects SSO (Single Sign On): from 1.0 before 1.1.

πŸ“… Published: June 26, 2024, 3:09 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-4228 - SQLi in Magarsus Consultancy's SSO

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 200 - Exposure of Sensitive Information to an Unauthorized Actor, CWE - 522 - Insufficiently Protected Credentials vulnerability in Magarsus Consultancy SSO (Single Sign On) allows SQL Injection.This issue a…

πŸ“… Published: June 26, 2024, 2:28 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 9324 of 34,919
Β« previous page Β» next page
Filters