7.5

CVSS3.1

CVE-2024-29078 -

Incorrect permission assignment for critical resource issue exists in MosP kintai kanri V4.6.6 and earlier, which may allow a remote unauthenticated attacker with access to the product to alter the product settings.

πŸ“… Published: May 27, 2024, 11:52 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-28880 -

Path traversal vulnerability in MosP kintai kanri V4.6.6 and earlier allows a remote attacker who can log in to the product to obtain sensitive information of the product.

πŸ“… Published: May 27, 2024, 11:50 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2024-36428 -

OrangeHRM 3.3.3 allows admin/viewProjects sortOrder SQL injection.

πŸ“… Published: May 27, 2024, 10:48 p.m. πŸ”„ Last Modified: June 23, 2025, 6:09 p.m.

6.1

CVSS3.1

CVE-2024-34923 -

In Avocent DSR2030 Appliance firmware 03.04.00.07 before 03.07.01.23, and SVIP1020 Appliance firmware 01.06.00.03 before 01.07.00.00, there is reflected cross-site scripting (XSS).

πŸ“… Published: May 27, 2024, 7:49 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS3.1

CVE-2024-35182 - GHSL-2024-014 Meshery SQL Injection vulnerability

Meshery is an open source, cloud native manager that enables the design and management of Kubernetes-based infrastructure and applications. A SQL injection vulnerability in Meshery prior to version 0.7.22 may lead to arbitrary file write by using a SQL injection stacked queries payload, and the ATT…

πŸ“… Published: May 27, 2024, 6:18 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 8:41 p.m.

5.9

CVSS3.1

CVE-2024-35181 - GHSL-2024-013 Meshery SQL Injection vulnerability

Meshery is an open source, cloud native manager that enables the design and management of Kubernetes-based infrastructure and applications. A SQL injection vulnerability in Meshery prior to version 0.7.22 may lead to arbitrary file write by using a SQL injection stacked queries payload, and the ATT…

πŸ“… Published: May 27, 2024, 6:18 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 8:46 p.m.

8.1

CVSS3.1

CVE-2024-5154 - Cri-o: malicious container can create symlink on host

A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (β€œ../β€œ). This flaw allows the container to read and write to arbitrary files on the host system.

πŸ“… Published: May 27, 2024, 6 p.m. πŸ”„ Last Modified: Feb. 25, 2026, 10:23 p.m.

5.5

CVSS3.1

CVE-2024-36037 - Insufficient Access Control Vulnerability

Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to view the session recordings.

πŸ“… Published: May 27, 2024, 5:59 p.m. πŸ”„ Last Modified: Nov. 27, 2024, 4:24 p.m.

4.2

CVSS3.1

CVE-2024-36036 - Insufficient Access Control Vulnerability

Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to access sensitive information and modifying the agent configuration.

πŸ“… Published: May 27, 2024, 5:58 p.m. πŸ”„ Last Modified: May 16, 2025, 4:58 p.m.

5.3

CVSS3.1

CVE-2024-27310 - DOS Vulnerability

Zoho ManageEngineΒ ADSelfService Plus versions belowΒ 6401 are vulnerable to the DOS attack due to the malicious LDAP input.

πŸ“… Published: May 27, 2024, 5:26 p.m. πŸ”„ Last Modified: Nov. 27, 2024, 4:25 p.m.
Total resulsts: 349182
Page 9660 of 34,919
Β« previous page Β» next page
Filters