5.4

CVSS3.1

CVE-2024-30140 - HCL BigFix Compliance is affected by unvalidated redirects and forwards

HCL BigFix Compliance is affected by unvalidated redirects and forwards. The HOST header can be manipulated by an attacker and as a result, it can poison the web cache and provide back to users being served the page.

πŸ“… Published: Nov. 7, 2024, 8:17 a.m. πŸ”„ Last Modified: June 17, 2025, 9:03 p.m.

4.8

CVSS3.1

CVE-2024-10027 - WP Booking Calendar < 10.6.3 - Admin+ Stored XSS

The WP Booking Calendar WordPress plugin before 10.6.3 does not sanitise and escape some of its Widgets settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setu…

πŸ“… Published: Nov. 7, 2024, 6 a.m. πŸ”„ Last Modified: May 15, 2025, 5:19 p.m.

5.1

CVSS4.0

CVE-2024-10947 - Guangzhou Tuchuang Computer Software Development Interlib Library Cluster Automation Management Sys…

A vulnerability classified as critical was found in Guangzhou Tuchuang Computer Software Development Interlib Library Cluster Automation Management System up to 2.0.1. This vulnerability affects unknown code of the file /interlib/order/BatchOrder?cmdACT=admin_order&xsl=adminOrder_OrderList.xsl. The…

πŸ“… Published: Nov. 7, 2024, 3:31 a.m. πŸ”„ Last Modified: Dec. 11, 2024, 7:58 p.m.

5.1

CVSS4.0

CVE-2024-10946 - Guangzhou Tuchuang Computer Software Development Interlib Library Cluster Automation Management Sys…

A vulnerability classified as critical has been found in Guangzhou Tuchuang Computer Software Development Interlib Library Cluster Automation Management System up to 2.0.1. This affects an unknown part of the file /interlib/admin/SysLib?cmdACT=inputLIBCODE&mod=batchXSL&xsl=editLIBCODE.xsl&libcodes=…

πŸ“… Published: Nov. 7, 2024, 3:31 a.m. πŸ”„ Last Modified: Dec. 11, 2024, 7:58 p.m.

0.0

CVE-2024-10922 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-51647. Reason: This candidate is a reservation duplicate of CVE-2024-51647. Notes: All CVE users should reference CVE-2024-51647 instead of this candidate. All references and descriptions in this candidate have been removed to prev…

πŸ“… Published: Nov. 7, 2024, 1:57 a.m. πŸ”„ Last Modified: Dec. 12, 2024, 6:15 p.m.

9.3

CVSS4.0

CVE-2024-51990 - Path traversal via crafted Git repositories in jj

jj, or Jujutsu, is a Git-compatible VCS written in rust. In affected versions specially crafted Git repositories can cause `jj` to write files outside the clone. This issue has been addressed in version 0.23.0. Users are advised to upgrade. Users unable to upgrade should avoid cloning repos from un…

πŸ“… Published: Nov. 7, 2024, 12:15 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.2

CVSS3.1

CVE-2019-20472 -

An issue was discovered on One2Track 2019-12-08 devices. Any SIM card used with the device cannot have a PIN configured. If a PIN is configured, the device simply produces a "Remove PIN and restart!" message, and cannot be used. This makes it easier for an attacker to use the SIM card by stealing t…

πŸ“… Published: Nov. 7, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2019-20462 -

An issue was discovered on Alecto IVM-100 2019-11-12 devices. The device comes with a serial interface at the board level. By attaching to this serial interface and rebooting the device, a large amount of information is disclosed. This includes the view password and the password of the Wi-Fi access…

πŸ“… Published: Nov. 7, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2024-50143 - udf: fix uninit-value use in udf_get_fileshortad

In the Linux kernel, the following vulnerability has been resolved: udf: fix uninit-value use in udf_get_fileshortad Check for overflow when computing alen in udf_current_aext to mitigate later uninit-value use in udf_get_fileshortad KMSAN bug[1]. After applying the patch reproducer did not trigg…

πŸ“… Published: Nov. 7, 2024, midnight πŸ”„ Last Modified: Jan. 5, 2026, 10:55 a.m.

7.4

CVSS3.1

CVE-2024-10963 - Pam: improper hostname interpretation in pam_access leads to access control bypass

A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames. This vulnerability allows attackers to trick the system by pretending to be a trusted hostname, gaining unauthorized access. This issue poses a risk for systems that rely on this featu…

πŸ“… Published: Nov. 7, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 345002
Page 7576 of 34,501
Β« previous page Β» next page
Filters