4.7

CVSS3.1

CVE-2024-47588 - Information Disclosure vulnerability in SAP NetWeaver Java (Software Update Manager)

In SAP NetWeaver Java (Software Update Manager 1.1), under certain conditions when a software upgrade encounters errors, credentials are written in plaintext to a log file. An attacker with local access to the server, authenticated as a non-administrative user, can acquire the credentials from the …

πŸ“… Published: Nov. 12, 2024, 12:26 a.m. πŸ”„ Last Modified: Nov. 12, 2024, 8:13 p.m.

3.5

CVSS3.1

CVE-2024-47587 - Missing authorization check in SAP Cash Management (Cash Operations)

Cash Operations does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges causing low impact to confidentiality to the application.

πŸ“… Published: Nov. 12, 2024, 12:26 a.m. πŸ”„ Last Modified: Nov. 12, 2024, 8:13 p.m.

5.3

CVSS3.1

CVE-2024-47586 - NULL Pointer Dereference vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platfo…

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated attacker to send a maliciously crafted http request which could cause a null pointer dereference in the kernel. This dereference will result in the system crashing and rebooting, causing the system to be temporari…

πŸ“… Published: Nov. 12, 2024, 12:25 a.m. πŸ”„ Last Modified: Nov. 12, 2024, 5:14 p.m.

6.5

CVSS3.1

CVE-2024-42372 - Missing Authorization check in SAP NetWeaver AS Java (System Landscape Directory)

Due to missing authorization check in SAP NetWeaver AS Java (System Landscape Directory) an unauthorized user can read and modify some restricted global SLD configurations causing low impact on confidentiality and integrity of the application.

πŸ“… Published: Nov. 12, 2024, 12:25 a.m. πŸ”„ Last Modified: Nov. 12, 2024, 1:55 p.m.

6.6

CVSS3.1

CVE-2024-28728 -

Cross Site Scripting vulnerability in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to obtain sensitive information via a crafted payload to the WiFi SSID Name field.

πŸ“… Published: Nov. 12, 2024, midnight πŸ”„ Last Modified: July 13, 2025, 11:14 a.m.

6.1

CVSS3.1

CVE-2021-27703 -

Sercomm Model Etisalat Model S3- AC2100 is affected by Cross Site Scripting (XSS) via the firmware update page.

πŸ“… Published: Nov. 12, 2024, midnight πŸ”„ Last Modified: Nov. 15, 2024, 10:35 p.m.

9.8

CVSS3.1

CVE-2024-43498 - .NET and Visual Studio Remote Code Execution Vulnerability

.NET and Visual Studio Remote Code Execution Vulnerability

πŸ“… Published: Nov. 12, 2024, midnight πŸ”„ Last Modified: July 8, 2025, 3:41 p.m.

7.5

CVSS3.1

CVE-2024-43499 - .NET and Visual Studio Denial of Service Vulnerability

.NET and Visual Studio Denial of Service Vulnerability

πŸ“… Published: Nov. 12, 2024, midnight πŸ”„ Last Modified: Aug. 27, 2025, 9:33 p.m.

9.1

CVSS3.1

CVE-2023-52268 -

The End-User Portal module before 1.0.65 for FreeScout sometimes allows an attacker to authenticate as an arbitrary user because a session token can be sent to the /auth endpoint. NOTE: this module is not part of freescout-helpdesk/freescout on GitHub.

πŸ“… Published: Nov. 12, 2024, midnight πŸ”„ Last Modified: Nov. 19, 2024, 5:35 p.m.

4.6

CVSS3.1

CVE-2024-28730 -

Cross Site Scripting vulnerability in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to obtain sensitive information via the file upload feature of the VPN configuration module.

πŸ“… Published: Nov. 12, 2024, midnight πŸ”„ Last Modified: Nov. 22, 2024, 3:07 p.m.
Total resulsts: 343968
Page 7419 of 34,397
Β« previous page Β» next page
Filters