8.1

CVSS3.1

CVE-2024-37300 - Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0

OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. JupyterHub < 5.0, when used with `GlobusOAuthenticator`, could be configured to allow all users from a particular institution only. This worked fine prior to JupyterHub 5.0, because `allow_al…

πŸ“… Published: June 12, 2024, 3:20 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-37297 - WooCommerce has a Cross-Site Scripting Vulnerability in checkout & registration forms

WooCommerce is an open-source e-commerce platform built on WordPress. A vulnerability introduced in WooCommerce 8.8 allows for cross-site scripting. A bad actor can manipulate a link to include malicious HTML & JavaScript content. While the content is not saved to the database, the links may be sen…

πŸ“… Published: June 12, 2024, 3:05 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:23 a.m.

7.8

CVSS3.1

CVE-2024-28964 -

Dell Common Event Enabler, version 8.9.10.0 and prior, contain an insecure deserialization vulnerability in CAVATools. A local unauthenticated attacker could potentially exploit this vulnerability, leading to arbitrary code execution in the context of the logged in user. Exploitation of this issue …

πŸ“… Published: June 12, 2024, 3:02 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:07 a.m.

6.2

CVSS3.1

CVE-2024-2300 - HP Advance Mobile Application – Potential Information Disclosure

HP Advance Mobile Applications for iOS and Android are potentially vulnerable to information disclosure when using an outdated version of the application via mobile devices.

πŸ“… Published: June 12, 2024, 3 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-5895 - SourceCodester Employee and Visitor Gate Pass Logging System delete_users sql injection

A vulnerability, which was classified as critical, has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. This issue affects the function delete_users of the file /classes/Users.php?f=delete. The manipulation of the argument id leads to sql injection. The attack may be …

πŸ“… Published: June 12, 2024, 3 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:48 a.m.

6.9

CVSS4.0

CVE-2024-5894 - SourceCodester Online Eyewear Shop manage_product.php sql injection

A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. This vulnerability affects unknown code of the file manage_product.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the…

πŸ“… Published: June 12, 2024, 3 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:48 a.m.

7.1

CVSS3.1

CVE-2024-34065 - @strapi/plugin-users-permissions leaks 3rd party authentication tokens and authentication bypass

Strapi is an open-source content management system. By combining two vulnerabilities (an `Open Redirect` and `session token sent as URL query parameter`) in @strapi/plugin-users-permissions before version 4.24.2, is its possible of an unauthenticated attacker to bypass authentication mechanisms and…

πŸ“… Published: June 12, 2024, 2:54 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:18 a.m.

5.3

CVSS3.1

CVE-2024-31217 - @strapi/plugin-upload has a Denial-of-Service via Improper Exception Handling

Strapi is an open-source content management system. Prior to version 4.22.0, a denial-of-service vulnerability is present in the media upload process causing the server to crash without restarting, affecting either development and production environments. Usually, errors in the application cause it…

πŸ“… Published: June 12, 2024, 2:50 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:13 a.m.

2.3

CVSS3.1

CVE-2024-29181 - @strapi/plugin-content-manager leaks data via relations via the Admin Panel

Strapi is an open-source content management system. Prior to version 4.19.1, a super admin can create a collection where an item in the collection has an association to another collection. When this happens, another user with Author Role can see the list of associated items they did not create. The…

πŸ“… Published: June 12, 2024, 2:46 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:07 a.m.

5.3

CVSS4.0

CVE-2024-5893 - SourceCodester Cab Management System sql injection

A vulnerability classified as critical has been found in SourceCodester Cab Management System 1.0. This affects an unknown part of the file /cms/classes/Users.php?f=delete_client. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit…

πŸ“… Published: June 12, 2024, 2:31 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:48 a.m.
Total resulsts: 349182
Page 9483 of 34,919
Β« previous page Β» next page
Filters