9.1

CVSS3.1

CVE-2024-46505 -

Infoblox BloxOne v2.4 was discovered to contain a business logic flaw due to thick client vulnerabilities.

๐Ÿ“… Published: Jan. 9, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 23, 2025, 6:15 p.m.

7.8

CVSS3.1

CVE-2024-46464 -

In PRIMX ZED Enterprise up to 2024.3, technical files stored in local folders with common user access can be manipulated to render the host computer unavailable or to execute programs with an elevation of privilege.

๐Ÿ“… Published: Jan. 9, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 10, 2025, 6:15 p.m.

6.1

CVSS3.1

CVE-2024-55494 -

A PHP Code Injection vulnerability that can lead to Remote Code Execution (RCE) and XSS in Opencode Mobile Collect Call v5.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the op_func parameter at /occontrolpanel/index.php.

๐Ÿ“… Published: Jan. 9, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 13, 2025, 10:15 p.m.

5.4

CVSS3.1

CVE-2024-42898 -

A cross-site scripting (XSS) vulnerability in Nagios XI 2024R1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter in the Account Settings page.

๐Ÿ“… Published: Jan. 9, 2025, midnight ๐Ÿ”„ Last Modified: June 24, 2025, 2:27 p.m.

8

CVSS3.1

CVE-2024-54887 -

TP-Link TL-WR940N V3 and V4 with firmware 3.16.9 and earlier contain a buffer overflow via the dnsserver1 and dnsserver2 parameters at /userRpm/Wan6to4TunnelCfgRpm.htm. This vulnerability allows an authenticated attacker to execute arbitrary code on the remote device in the context of the root user.

๐Ÿ“… Published: Jan. 9, 2025, midnight ๐Ÿ”„ Last Modified: June 20, 2025, 6:35 p.m.

5.4

CVSS3.1

CVE-2024-55226 -

Vaultwarden v1.32.5 was discovered to contain an authenticated reflected cross-site scripting (XSS) vulnerability via the component /api/core/mod.rs.

๐Ÿ“… Published: Jan. 9, 2025, midnight ๐Ÿ”„ Last Modified: June 24, 2025, 2:01 p.m.

7.5

CVSS3.1

CVE-2024-56113 -

Smart Toilet Lab - Motius 1.3.11 is running with debug mode turned on (DEBUG = True) and exposing sensitive information defined in Django settings file through verbose error page.

๐Ÿ“… Published: Jan. 9, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 23, 2025, 6:15 p.m.

5.4

CVSS3.1

CVE-2024-56376 -

A stored cross-site scripting (XSS) vulnerability in the built-in messenger of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the message field. When a user click on the received message, the crafted payload is executed, potentially enabling the execution of arbitrary webโ€ฆ

๐Ÿ“… Published: Jan. 9, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 16, 2025, 9:10 p.m.

9.8

CVSS3.1

CVE-2024-54724 -

PHPYun before 7.0.2 is vulnerable to code execution through backdoor-restricted arbitrary file writing and file inclusion.

๐Ÿ“… Published: Jan. 9, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 21, 2025, 4:15 p.m.

9.8

CVSS3.1

CVE-2024-55225 -

An issue in the component src/api/identity.rs of Vaultwarden prior to v1.32.5 allows attackers to impersonate users, including Administrators, via a crafted authorization request.

๐Ÿ“… Published: Jan. 9, 2025, midnight ๐Ÿ”„ Last Modified: June 20, 2025, 6:29 p.m.
Total resulsts: 343968
Page 6698 of 34,397
ยซ previous page ยป next page
Filters