7.5

CVSS3.1

CVE-2024-48809 -

An issue in Open Networking Foundations sdran-in-a-box v.1.4.3 and onos-a1t v.0.2.3 allows a remote attacker to cause a denial of service via the onos-a1t component of the sdran-in-a-box, specifically the DeleteWatcher function.

๐Ÿ“… Published: Nov. 4, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 6, 2024, 7:33 p.m.

9.8

CVSS3.1

CVE-2024-51136 -

An XML External Entity (XXE) vulnerability in Dmoz2CSV in openimaj v1.3.10 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted XML file.

๐Ÿ“… Published: Nov. 4, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 6, 2024, 7:31 p.m.

9.8

CVSS3.1

CVE-2024-48050 -

In agentscope <=v0.0.4, the file agentscope\web\workstation\workflow_utils.py has the function is_callable_expression. Within this function, the line result = eval(s) poses a security risk as it can directly execute user-provided commands.

๐Ÿ“… Published: Nov. 4, 2024, midnight ๐Ÿ”„ Last Modified: Sept. 4, 2025, 4:26 p.m.

8

CVSS3.1

CVE-2024-45890 -

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `download_ovpn.`

๐Ÿ“… Published: Nov. 4, 2024, midnight ๐Ÿ”„ Last Modified: April 10, 2025, 3:52 p.m.

8

CVSS3.1

CVE-2024-45889 -

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `commandTable.`

๐Ÿ“… Published: Nov. 4, 2024, midnight ๐Ÿ”„ Last Modified: April 10, 2025, 3:52 p.m.

6.8

CVSS3.1

CVE-2024-34882 -

Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send SMTP account passwords to an arbitrary server via HTTP POST request.

๐Ÿ“… Published: Nov. 4, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 6, 2024, 7:28 p.m.

5.4

CVSS3.1

CVE-2024-30617 -

A Cross-Site Request Forgery (CSRF) vulnerability in Chamilo LMS 1.11.26 "/main/social/home.php," allows attackers to initiate a request that posts a fake post onto the user's social wall without their consent or knowledge.

๐Ÿ“… Published: Nov. 4, 2024, midnight ๐Ÿ”„ Last Modified: April 18, 2025, 1:55 p.m.

6.1

CVSS3.1

CVE-2024-48057 -

localai <=2.20.1 is vulnerable to Cross Site Scripting (XSS). When calling the delete model API and passing inappropriate parameters, it can cause a one-time storage XSS, which will trigger the payload when a user accesses the homepage.

๐Ÿ“… Published: Nov. 4, 2024, midnight ๐Ÿ”„ Last Modified: Sept. 4, 2025, 4:15 p.m.

8

CVSS3.1

CVE-2024-45891 -

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `delete_wlan_profile.`

๐Ÿ“… Published: Nov. 4, 2024, midnight ๐Ÿ”„ Last Modified: April 10, 2025, 3:52 p.m.

7.5

CVSS3.1

CVE-2024-51326 -

SQL Injection vulnerability in projectworlds Travel management System v.1.0 allows a remote attacker to execute arbitrary code via the 't2' parameter in deletesubcategory.php.

๐Ÿ“… Published: Nov. 4, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 6, 2024, 3:02 p.m.
Total resulsts: 342358
Page 7361 of 34,236
ยซ previous page ยป next page
Filters