6.1

CVSS3.1

CVE-2024-37156 - TokenController formName not sanitized in hidden input

The SuluFormBundle adds support for creating dynamic forms in Sulu Admin. The TokenController get parameter formName is not sanitized in the returned input field which leads to XSS. This vulnerability is fixed in 2.5.3.

πŸ“… Published: June 6, 2024, 4:03 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:23 a.m.

7.5

CVSS3.1

CVE-2024-35178 - Jupyter server on Windows discloses Windows user password hash

The Jupyter Server provides the backend for Jupyter web applications. Jupyter Server on Windows has a vulnerability that lets unauthenticated attackers leak the NTLMv2 password hash of the Windows user running the Jupyter server. An attacker can crack this password to gain access to the Windows mac…

πŸ“… Published: June 6, 2024, 3:37 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:19 a.m.

7.6

CVSS3.1

CVE-2024-37150 - Private npm registry support used scope auth token for downloading tarballs

An issue in `.npmrc` support in Deno 1.44.0 was discovered where Deno would send `.npmrc` credentials for the scope to the tarball URL when the registry provided URLs for a tarball on a different domain. All users relying on .npmrc are potentially affected by this vulnerability if their private reg…

πŸ“… Published: June 6, 2024, 3:28 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:23 a.m.

8.2

CVSS3.1

CVE-2024-36399 - Kanboard affected by Project Takeover via IDOR in ProjectPermissionController

Kanboard is project management software that focuses on the Kanban methodology. The vuln is in app/Controller/ProjectPermissionController.php function addUser(). The users permission to add users to a project only get checked on the URL parameter project_id. If the user is authorized to add users t…

πŸ“… Published: June 6, 2024, 3:15 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:22 a.m.

9.8

CVSS3.1

CVE-2024-34832 -

Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a crafted file uploaded to the _g and node parameters.

πŸ“… Published: June 6, 2024, 2:45 p.m. πŸ”„ Last Modified: Feb. 13, 2025, 3:53 p.m.

6.3

CVSS3.1

CVE-2024-5684 - ID Charger Connect & Pro - JWT-Null-Algorithm

An attacker with access to the private network (the charger is connected to) or local access to the Ethernet-Interface can exploit a faulty implementation of the JWT-library in order to bypass the password authentication to the web configuration interface and then has full access as the user would …

πŸ“… Published: June 6, 2024, 12:54 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:48 a.m.

9.8

CVSS3.1

CVE-2024-36779 -

Sourcecodester Stock Management System v1.0 is vulnerable to SQL Injection via editCategories.php.

πŸ“… Published: June 6, 2024, 12:31 p.m. πŸ”„ Last Modified: Feb. 13, 2025, 3:59 p.m.

10

CVSS3.1

CVE-2024-5675 - Unreliable data deserialization vulnerability in Mentor

Untrusted data deserialization vulnerability has been found in Mentor - Employee Portal, affecting version 3.83.35. This vulnerability could allow an attacker to execute arbitrary code, by injecting a malicious payload into the β€œViewState” field.

πŸ“… Published: June 6, 2024, 12:10 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:48 a.m.

4.3

CVSS3.1

CVE-2024-5489 - Wbcom Designs - Custom Font Uploader <= 2.3.4 - Missing Authorization to Font Deletion

The Wbcom Designs – Custom Font Uploader plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'cfu_delete_customfont' function in all versions up to, and including, 2.3.4. This makes it possible for authenticated attackers, with Subscriber-level a…

πŸ“… Published: June 6, 2024, 11:33 a.m. πŸ”„ Last Modified: April 8, 2026, 5:19 p.m.

6.4

CVSS3.1

CVE-2024-5188 - Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= …

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'get_manual_calendar_events' function in all versions up to, and including, 5.9.22 due to insufficient input sanitization and…

πŸ“… Published: June 6, 2024, 11:03 a.m. πŸ”„ Last Modified: April 8, 2026, 6:22 p.m.
Total resulsts: 349182
Page 9568 of 34,919
Β« previous page Β» next page
Filters