6.4

CVSS3.1

CVE-2024-5173 - HT Mega – Absolute Addons For Elementor <= 2.5.5 - Authenticated (Contributor+) Stored Cross-Site S…

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Video player widget settings in all versions up to, and including, 2.5.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possib…

πŸ“… Published: June 26, 2024, 2:07 a.m. πŸ”„ Last Modified: April 8, 2026, 7:21 p.m.

0.0

CVE-2024-6341 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“… Published: June 26, 2024, 1:20 a.m. πŸ”„ Last Modified: July 2, 2024, 6:15 p.m.

3.5

CVSS3.1

CVE-2024-24764 - October Open Redirect for Administrator Accounts

October is a self-hosted CMS platform based on the Laravel PHP Framework. This issue affects authenticated administrators who may be redirected to an untrusted URL using the PageFinder schema. The resolver for the page finder link schema (`october://`) allowed external links, therefore allowing an…

πŸ“… Published: June 26, 2024, 12:02 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 8:59 a.m.

6.1

CVSS3.1

CVE-2024-33328 -

A cross-site scripting (XSS) vulnerability in the component main.jsp of Lumisxp v15.0.x to v16.1.x allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the pageId parameter.

πŸ“… Published: June 26, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4

CVSS3.1

CVE-2024-23765 -

An issue was discovered on HMS Anybus X-Gateway AB7832-F 3 devices. The gateway exposes an unidentified service on port 7412 on the network. All the network services of the gateway become unresponsive after sending 85 requests to this port. The content and length of the frame does not matter. The d…

πŸ“… Published: June 26, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-39241 -

Cross Site Scripting (XSS) vulnerability in skycaiji 2.8 allows attackers to run arbitrary code via /admin/tool/preview.

πŸ“… Published: June 26, 2024, midnight πŸ”„ Last Modified: March 18, 2025, 7:15 p.m.

4.3

CVSS3.1

CVE-2024-37571 -

Buffer Overflow vulnerability in SAS Broker 9.2 build 1495 allows attackers to cause denial of service or obtain sensitive information via crafted payload to the '_debug' parameter.

πŸ“… Published: June 26, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-33329 -

A hardcoded privileged ID within Lumisxp v15.0.x to v16.1.x allows attackers to bypass authentication and access internal pages and other sensitive information.

πŸ“… Published: June 26, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-35545 -

MAP-OS v4.45.0 and earlier was discovered to contain a cross-site scripting (XSS) vulnerability.

πŸ“… Published: June 26, 2024, midnight πŸ”„ Last Modified: July 3, 2025, 4:29 p.m.

8.8

CVSS3.1

CVE-2024-23767 -

An issue was discovered on HMS Anybus X-Gateway AB7832-F firmware version 3. The HICP protocol allows unauthenticated changes to a device's network configurations.

πŸ“… Published: June 26, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 9328 of 34,919
Β« previous page Β» next page
Filters