6.8

CVSS3.1

CVE-2024-34882 -

Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send SMTP account passwords to an arbitrary server via HTTP POST request.

πŸ“… Published: Nov. 4, 2024, midnight πŸ”„ Last Modified: Nov. 6, 2024, 7:28 p.m.

5.4

CVSS3.1

CVE-2024-30617 -

A Cross-Site Request Forgery (CSRF) vulnerability in Chamilo LMS 1.11.26 "/main/social/home.php," allows attackers to initiate a request that posts a fake post onto the user's social wall without their consent or knowledge.

πŸ“… Published: Nov. 4, 2024, midnight πŸ”„ Last Modified: April 18, 2025, 1:55 p.m.

6.1

CVSS3.1

CVE-2024-48057 -

localai <=2.20.1 is vulnerable to Cross Site Scripting (XSS). When calling the delete model API and passing inappropriate parameters, it can cause a one-time storage XSS, which will trigger the payload when a user accesses the homepage.

πŸ“… Published: Nov. 4, 2024, midnight πŸ”„ Last Modified: Sept. 4, 2025, 4:15 p.m.

8

CVSS3.1

CVE-2024-45891 -

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `delete_wlan_profile.`

πŸ“… Published: Nov. 4, 2024, midnight πŸ”„ Last Modified: April 10, 2025, 3:52 p.m.

7.5

CVSS3.1

CVE-2024-51326 -

SQL Injection vulnerability in projectworlds Travel management System v.1.0 allows a remote attacker to execute arbitrary code via the 't2' parameter in deletesubcategory.php.

πŸ“… Published: Nov. 4, 2024, midnight πŸ”„ Last Modified: Nov. 6, 2024, 3:02 p.m.

6.5

CVSS3.1

CVE-2024-48052 -

In gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The reason is that within the save_url_to_cache function, there are no restrictions on the URL, which allows access to local target resources. This can lead to the download of local res…

πŸ“… Published: Nov. 4, 2024, midnight πŸ”„ Last Modified: June 13, 2025, 12:21 a.m.

8

CVSS3.1

CVE-2024-45884 -

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `setSWMGroup.`

πŸ“… Published: Nov. 4, 2024, midnight πŸ”„ Last Modified: April 10, 2025, 3:52 p.m.

6.8

CVSS3.1

CVE-2024-34887 -

Insufficiently protected credentials in AD/LDAP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send AD/LDAP administrators account passwords to an arbitrary server via HTTP POST request.

πŸ“… Published: Nov. 4, 2024, midnight πŸ”„ Last Modified: Nov. 6, 2024, 7:28 p.m.

7.5

CVSS3.1

CVE-2024-30619 -

Chamilo LMS Version 1.11.26 is vulnerable to Incorrect Access Control. A non-authenticated attacker can request the number of messages and the number of online users via "/main/inc/ajax/message.ajax.php?a=get_count_message" AND "/main/inc/ajax/online.ajax.php?a=get_users_online."

πŸ“… Published: Nov. 4, 2024, midnight πŸ”„ Last Modified: April 18, 2025, 1:52 p.m.

9.1

CVSS3.1

CVE-2024-51127 - hornetq-core-client: Arbitrarily overwrite files or access sensitive information

An issue in the createTempFile method of hornetq v2.4.9 allows attackers to arbitrarily overwrite files or access sensitive information.

πŸ“… Published: Nov. 4, 2024, midnight πŸ”„ Last Modified: Nov. 21, 2024, 9:45 a.m.
Total resulsts: 342363
Page 7362 of 34,237
Β« previous page Β» next page
Filters