8.8

CVSS3.1

CVE-2024-51492 - Zusam vulnerable to stored XSS, allowing token theft via crafted SVG

Zusam is a free and open-source way to self-host private forums. Prior to version 0.5.6, specially crafted SVG files uploaded to the service as images allow for unrestricted script execution on (raw) image load. With certain payloads, theft of the target userโ€™s long-lived session token is possible.โ€ฆ

๐Ÿ“… Published: Nov. 1, 2024, 4:22 p.m. ๐Ÿ”„ Last Modified: Nov. 1, 2024, 9:15 p.m.

0.0

CVE-2024-10694 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-9542. Reason: This candidate is a reservation duplicate of CVE-2024-9542. Notes: All CVE users should reference CVE-2024-9542 instead of this candidate. All references and descriptions in this candidate have been removed to preventโ€ฆ

๐Ÿ“… Published: Nov. 1, 2024, 4:20 p.m. ๐Ÿ”„ Last Modified: Nov. 11, 2024, 9:15 p.m.

6.9

CVSS4.0

CVE-2024-51483 - changedetection.io Path Traversal vulnerability

changedetection.io is free, open source web page change detection software. Prior to version 0.47.5, when a WebDriver is used to fetch files, `source:file:///etc/passwd` can be used to retrieve local system files, where the more traditional `file:///etc/passwd` gets blocked. Version 0.47.5 fixes thโ€ฆ

๐Ÿ“… Published: Nov. 1, 2024, 4:19 p.m. ๐Ÿ”„ Last Modified: Nov. 1, 2024, 8:24 p.m.

7.7

CVSS4.0

CVE-2024-49770 - oak's path traversal allows transfer of hidden files within the served root directory

`oak` is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers and Bun. By default `oak` does not allow transferring of hidden files with `Context.send` API. However, prior to version 17.1.3, this can be bypassed by encoding `/` as its URL encโ€ฆ

๐Ÿ“… Published: Nov. 1, 2024, 4:16 p.m. ๐Ÿ”„ Last Modified: Nov. 1, 2024, 8:24 p.m.

8.7

CVSS4.0

CVE-2024-10662 - Tenda AC15 SetOnlineDevName formSetDeviceName stack-based overflow

A vulnerability was found in Tenda AC15 15.03.05.19 and classified as critical. This issue affects the function formSetDeviceName of the file /goform/SetOnlineDevName. The manipulation of the argument devName leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit haโ€ฆ

๐Ÿ“… Published: Nov. 1, 2024, 4 p.m. ๐Ÿ”„ Last Modified: Nov. 5, 2024, 3:25 p.m.

8.7

CVSS4.0

CVE-2024-10661 - Tenda AC15 SetDlnaCfg stack-based overflow

A vulnerability has been found in Tenda AC15 15.03.05.19 and classified as critical. This vulnerability affects the function SetDlnaCfg of the file /goform/SetDlnaCfg. The manipulation of the argument scanList leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit hโ€ฆ

๐Ÿ“… Published: Nov. 1, 2024, 4 p.m. ๐Ÿ”„ Last Modified: Nov. 5, 2024, 3:26 p.m.

0.0

CVE-2024-10691 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-9530. Reason: This candidate is a reservation duplicate of CVE-2024-9530. Notes: All CVE users should reference CVE-2024-9530 instead of this candidate. All references and descriptions in this candidate have been removed to preventโ€ฆ

๐Ÿ“… Published: Nov. 1, 2024, 3:32 p.m. ๐Ÿ”„ Last Modified: Nov. 15, 2024, 3:15 p.m.

5.3

CVSS4.0

CVE-2024-10660 - ESAFENET CDG HookService.java deleteHook sql injection

A vulnerability, which was classified as critical, was found in ESAFENET CDG 5. This affects the function deleteHook of the file /com/esafenet/servlet/policy/HookService.java. The manipulation of the argument hookId leads to sql injection. It is possible to initiate the attack remotely. The exploitโ€ฆ

๐Ÿ“… Published: Nov. 1, 2024, 3:31 p.m. ๐Ÿ”„ Last Modified: Nov. 5, 2024, 5:04 p.m.

5.3

CVSS4.0

CVE-2024-10659 - ESAFENET CDG CDGAuthoriseTempletService.java delSystemEncryptPolicy sql injection

A vulnerability, which was classified as critical, has been found in ESAFENET CDG 5. Affected by this issue is the function delSystemEncryptPolicy of the file /com/esafenet/servlet/document/CDGAuthoriseTempletService.java. The manipulation of the argument id leads to sql injection. The attack may bโ€ฆ

๐Ÿ“… Published: Nov. 1, 2024, 3:31 p.m. ๐Ÿ”„ Last Modified: Nov. 5, 2024, 5:04 p.m.

5.3

CVSS4.0

CVE-2024-10658 - Tongda OA check_seal.php sql injection

A vulnerability classified as critical was found in Tongda OA up to 11.10. Affected by this vulnerability is an unknown functionality of the file /pda/approve_center/check_seal.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has beenโ€ฆ

๐Ÿ“… Published: Nov. 1, 2024, 3 p.m. ๐Ÿ”„ Last Modified: Nov. 4, 2024, 7:46 p.m.
Total resulsts: 342358
Page 7368 of 34,236
ยซ previous page ยป next page
Filters