6.5

CVSS3.1

CVE-2024-31400 -

Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.0.0 to 5.15.0. If this vulnerability is exploited, unintended data may be left in forwarded mail.

πŸ“… Published: June 11, 2024, 4:26 a.m. πŸ”„ Last Modified: Aug. 5, 2025, 3:37 p.m.

9.8

CVSS3.1

CVE-2024-36360 -

OS command injection vulnerability exists in awkblog v0.0.1 (commit hash:7b761b192d0e0dc3eef0f30630e00ece01c8d552) and earlier. If a remote unauthenticated attacker sends a specially crafted HTTP request, an arbitrary OS command may be executed with the privileges of the affected product on the mac…

πŸ“… Published: June 11, 2024, 4:19 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9

CVSS3.0

CVE-2024-29855 -

Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator

πŸ“… Published: June 11, 2024, 3:55 a.m. πŸ”„ Last Modified: July 14, 2025, 8:21 p.m.

8.1

CVSS3.1

CVE-2023-7264 - Build App Online <= 1.0.22 - Account Takeover via Weak Password Reset Mechanism

The Build App Online plugin for WordPress is vulnerable to account takeover due to a weak password reset mechanism in all versions up to, and including, 1.0.22. This makes it possible for unauthenticated attackers to reset the password of arbitrary users by guessing an 4-digit numeric reset code.

πŸ“… Published: June 11, 2024, 3:16 a.m. πŸ”„ Last Modified: April 8, 2026, 7:19 p.m.

6.5

CVSS3.1

CVE-2024-34691 - Missing Authorization check in SAP S/4HANA (Manage Incoming Payment Files)

Manage Incoming Payment Files (F1680) of SAP S/4HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. As a result, it has high impact on integrity and no impact on the confidentiality and availability of the system.

πŸ“… Published: June 11, 2024, 2:22 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:19 a.m.

3.7

CVSS3.1

CVE-2024-34684 - Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Schedul…

On Unix, SAP BusinessObjects Business Intelligence Platform (Scheduling) allows an authenticated attacker with administrator access on the local server to access the password of a local account. As a result, an attacker can obtain non-administrative user credentials, which will allow them to read o…

πŸ“… Published: June 11, 2024, 2:20 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:19 a.m.

5.3

CVSS3.1

CVE-2024-28164 - Information Disclosure vulnerability in SAP NetWeaver AS Java (Guided Procedures)

SAP NetWeaver AS Java (CAF - Guided Procedures) allows an unauthenticated user to access non-sensitive information about the server which would otherwise be restricted causing low impact on confidentiality of the application.

πŸ“… Published: June 11, 2024, 2:18 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:05 a.m.

5.4

CVSS3.1

CVE-2024-34690 - Missing Authorization check in SAP Student Life Cycle Management (SLcM)

SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading to the potential escalation of privileges. On successful exploitation it could allow an attacker to access and edit non-sensitive report variants that are typically restricted, cau…

πŸ“… Published: June 11, 2024, 2:17 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:19 a.m.

5.5

CVSS3.1

CVE-2024-37176 - Missing Authorization check in SAP BW/4HANA Transformation and DTP

SAP BW/4HANA Transformation and Data Transfer Process (DTP) allows an authenticated attacker to gain higher access levels than they should have by exploiting improper authorization checks. This results in escalation of privileges. It has no impact on the confidentiality of data but may have low imp…

πŸ“… Published: June 11, 2024, 2:14 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:23 a.m.

6.1

CVSS3.1

CVE-2024-34686 - Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)

Due to insufficient input validation, SAP CRM WebClient UI allows an unauthenticated attacker to craft a URL link which embeds a malicious script. When a victim clicks on this link, the script will be executed in the victim's browser giving the attacker the ability to access and/or modify informati…

πŸ“… Published: June 11, 2024, 2:11 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:19 a.m.
Total resulsts: 349182
Page 9510 of 34,919
Β« previous page Β» next page
Filters