7.1

CVSS3.1

CVE-2024-28736 -

An issue in Debezium Community debezium-ui v.2.5 allows a local attacker to execute arbitrary code via the refresh page function.

๐Ÿ“… Published: May 31, 2024, 3:41 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-36108 - Multiple Broken Function-Level Authorization vulnerabilities in casgate

casgate is an Open Source Identity and Access Management system. In affected versions `casgate` allows remote unauthenticated attacker to obtain sensitive information via GET request to an API endpoint. This issue has been addressed in PR #201 which is pending merge. An attacker could use `id` paraโ€ฆ

๐Ÿ“… Published: May 31, 2024, 2:37 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2023-7073 - Auto Featured Image (Auto Post Thumbnail) <= 4.1.7 - Authenticated (Author+) Server-Side Request Foโ€ฆ

The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.1.7 via the upload_to_library AJAX action. This makes it possible for authenticated attackers, with author-level access and above, to make web requโ€ฆ

๐Ÿ“… Published: May 31, 2024, 2:31 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2024-5565 - Prompt Injection in "ask" API with visualization leads to RCE

The Vanna library uses a prompt function to present the user with visualized results, it is possible to alter the prompt using prompt injection and run arbitrary Python code instead of the intended visualization code. Specifically - allowing external input to the libraryโ€™s โ€œaskโ€ method with "visualโ€ฆ

๐Ÿ“… Published: May 31, 2024, 2:24 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-31907 -

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 289889.

๐Ÿ“… Published: May 31, 2024, 1:09 p.m. ๐Ÿ”„ Last Modified: Jan. 8, 2025, 5:06 p.m.

6.4

CVSS3.1

CVE-2024-31908 - IBM Planning Analytics Local cross-site scripting

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: โ€ฆ

๐Ÿ“… Published: May 31, 2024, 1:05 p.m. ๐Ÿ”„ Last Modified: Jan. 8, 2025, 5:02 p.m.

5.4

CVSS3.1

CVE-2024-31889 - IBM Planning Analytics Local cross-site scripting

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 288136.

๐Ÿ“… Published: May 31, 2024, 12:57 p.m. ๐Ÿ”„ Last Modified: Jan. 8, 2025, 5:10 p.m.

4

CVSS3.1

CVE-2024-22338 - IBM Security Verify Access OIDC Provider information disclosure

IBM Security Verify Access OIDC Provider 22.09 through 23.03 could disclose sensitive information to a local user due to hazardous input validation. IBM X-Force ID: 279978.

๐Ÿ“… Published: May 31, 2024, 10:36 a.m. ๐Ÿ”„ Last Modified: Aug. 14, 2025, 7:18 p.m.

9.8

CVSS3.1

CVE-2024-23692 - Rejetto HTTP File Server 2.3m Unauthenticated RCE

Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request. As of the CVE assignment daโ€ฆ

๐Ÿ“… Published: May 31, 2024, 9:36 a.m. ๐Ÿ”„ Last Modified: Nov. 22, 2025, 12:13 p.m.

6.4

CVSS3.1

CVE-2024-5041 - Happy Addons for Elementor <= 3.10.9 - Authenticated (Contributor+) Stored Cross-Site Scripting viaโ€ฆ

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the โ€˜ha-ia-content-buttonโ€™ parameter in all versions up to, and including, 3.10.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, withโ€ฆ

๐Ÿ“… Published: May 31, 2024, 9:31 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 7:21 p.m.
Total resulsts: 349182
Page 9619 of 34,919
ยซ previous page ยป next page
Filters