6.1

CVSS3.1

CVE-2024-33231 -

Cross Site Scripting vulnerability in Ferozo Email version 1.1 allows a local attacker to execute arbitrary code via a crafted payload to the PDF preview component.

๐Ÿ“… Published: Nov. 18, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 19, 2024, 9:57 p.m.

6.5

CVSS3.1

CVE-2024-52926 -

Delinea Privilege Manager before 12.0.2 mishandles the security of the Windows agent.

๐Ÿ“… Published: Nov. 18, 2024, midnight ๐Ÿ”„ Last Modified: Jan. 6, 2025, 5:55 p.m.

7.5

CVSS3.1

CVE-2024-52916 -

Bitcoin Core before 0.15.0 allows a denial of service (OOM kill of a daemon process) via a flood of minimum difficulty headers.

๐Ÿ“… Published: Nov. 18, 2024, midnight ๐Ÿ”„ Last Modified: April 30, 2025, 4:16 p.m.

4.8

CVSS3.1

CVE-2024-50849 -

A Stored Cross-Site Scripting (XSS) vulnerability in the "Rules" functionality of WorldServer v11.8.2 allows a remote authenticated attacker to execute arbitrary JavaScript code.

๐Ÿ“… Published: Nov. 18, 2024, midnight ๐Ÿ”„ Last Modified: Oct. 20, 2025, 4:15 p.m.

6.5

CVSS3.1

CVE-2024-50848 -

An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to access sensitive information and execute arbitrary commands via supplying a crafted .tmx file.

๐Ÿ“… Published: Nov. 18, 2024, midnight ๐Ÿ”„ Last Modified: Oct. 20, 2025, 4:15 p.m.

9.8

CVSS3.1

CVE-2023-43091 - Gnome-maps: gnome maps is vulnerable to a code injection attack (similar to xss) via its service.jโ€ฆ

A flaw was found in GNOME Maps, which is vulnerable to a code injection attack via its service.json configuration file. If the configuration file is malicious, it may execute arbitrary code.

๐Ÿ“… Published: Nov. 17, 2024, 12:25 p.m. ๐Ÿ”„ Last Modified: Aug. 6, 2025, 12:46 p.m.

8.1

CVSS3.1

CVE-2024-52867 -

guix-daemon in GNU Guix before 5ab3c4c allows privilege escalation because build outputs are accessible by local users before file metadata concerns (e.g., for setuid and setgid programs) are properly addressed. The vulnerability can be remediated within the product via certain pull, reconfigure, aโ€ฆ

๐Ÿ“… Published: Nov. 17, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:46 a.m.

7.5

CVSS3.1

CVE-2024-52876 -

Holy Stone Remote ID Module HSRID01, firmware distributed with the Drone Go2 mobile application before 1.1.8, allows unauthenticated "remote power off" actions (in broadcast mode) via multiple read operations on the ASTM Remote ID (0xFFFA) GATT.

๐Ÿ“… Published: Nov. 17, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 18, 2024, 5:35 p.m.

7.5

CVSS3.1

CVE-2024-52871 -

In Flagsmith before 2.134.1, it is possible to bypass the ALLOW_REGISTRATION_WITHOUT_INVITE setting.

๐Ÿ“… Published: Nov. 17, 2024, midnight ๐Ÿ”„ Last Modified: July 7, 2025, 6:01 p.m.

7.5

CVSS3.1

CVE-2024-52872 -

In Flagsmith before 2.134.1, the get_document endpoint is not correctly protected by permissions.

๐Ÿ“… Published: Nov. 17, 2024, midnight ๐Ÿ”„ Last Modified: July 7, 2025, 5:59 p.m.
Total resulsts: 343992
Page 7324 of 34,400
ยซ previous page ยป next page
Filters