5.3

CVSS3.1

CVE-2024-20445 - Cisco IP Phone 7800, 8800, and 9800 Series Information Disclosure Vulnerability

A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could allow an unauthenticated, remote attacker to access sensitive information on an affected device. This vulnerability is due to improper storage of sensitive informa…

πŸ“… Published: Nov. 6, 2024, 4:29 p.m. πŸ”„ Last Modified: Jan. 5, 2026, 2:57 p.m.

4.3

CVSS3.1

CVE-2024-20476 - Cisco Identity Services Engine Authorization Bypass Vulnerability

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific file management functions. This vulnerability is due to lack of server-side validation of Administrator permissions. An attacker co…

πŸ“… Published: Nov. 6, 2024, 4:28 p.m. πŸ”„ Last Modified: April 4, 2025, 5:19 p.m.

5.3

CVSS3.1

CVE-2024-20371 - Cisco Nexus 3550-F Switches Access Control List Programming Vulnerability

A vulnerability in the access control list (ACL) programming of Cisco Nexus 3550-F Switches could allow an unauthenticated, remote attacker to send traffic that should be blocked to the management interface of an affected device.  This vulnerability exists because ACL deny rules are not pro…

πŸ“… Published: Nov. 6, 2024, 4:28 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-10827 -

Use after free in Serial in Google Chrome prior to 130.0.6723.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: Nov. 6, 2024, 4:09 p.m. πŸ”„ Last Modified: Jan. 2, 2025, 6:07 p.m.

8.8

CVSS3.1

CVE-2024-10826 -

Use after free in Family Experiences in Google Chrome on Android prior to 130.0.6723.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: Nov. 6, 2024, 4:09 p.m. πŸ”„ Last Modified: Jan. 2, 2025, 6:07 p.m.

2.3

CVSS4.0

CVE-2024-10920 - mariazevedo88 travels-java-api JWT Secret JwtAuthenticationTokenFilter.java doFilterInternal hard-c…

A vulnerability was found in mariazevedo88 travels-java-api up to 5.0.1 and classified as problematic. Affected by this issue is the function doFilterInternal of the file travels-java-api-master\src\main\java\io\github\mariazevedo88\travelsjavaapi\filters\JwtAuthenticationTokenFilter.java of the co…

πŸ“… Published: Nov. 6, 2024, 4 p.m. πŸ”„ Last Modified: Nov. 22, 2024, 8:05 p.m.

5.3

CVSS4.0

CVE-2024-10919 - didi Super-Jacoco triggerUnitCover os command injection

A vulnerability has been found in didi Super-Jacoco 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /cov/triggerUnitCover. The manipulation of the argument uuid leads to os command injection. The attack can be launched remotely. The exploit has…

πŸ“… Published: Nov. 6, 2024, 4 p.m. πŸ”„ Last Modified: Nov. 8, 2024, 9:07 p.m.

6.9

CVSS4.0

CVE-2024-10916 - D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L HTTP GET Request info.xml information disclosure

A vulnerability classified as problematic has been found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. This affects an unknown part of the file /xml/info.xml of the component HTTP GET Request Handler. The manipulation leads to information disclosure. It is possible to initiate …

πŸ“… Published: Nov. 6, 2024, 3 p.m. πŸ”„ Last Modified: Nov. 8, 2024, 8:11 p.m.

8.7

CVSS3.1

CVE-2024-10082 -

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication method confusion allows logging in as the built-in root user from an external service. The built-in root user up until 6.24.1 is generated in a weak manner, cannot …

πŸ“… Published: Nov. 6, 2024, 2:34 p.m. πŸ”„ Last Modified: Nov. 14, 2025, 5:24 p.m.

10

CVSS3.1

CVE-2024-10081 -

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs when the API URL ends with Authentication. This bypass allows superuser access to all API endpoints other than Authentication. These endpoints include…

πŸ“… Published: Nov. 6, 2024, 2:33 p.m. πŸ”„ Last Modified: Nov. 14, 2025, 4:36 p.m.
Total resulsts: 344963
Page 7583 of 34,497
Β« previous page Β» next page
Filters