4.3

CVSS3.1

CVE-2024-31972 -

EnGenius ESR580 A8J-EMR5000 devices allow a remote attacker to conduct stored XSS attacks that could lead to arbitrary JavaScript code execution (under the context of the user's session) via the Wi-Fi SSID input fields. Web scripts embedded into the vulnerable fields this way are executed immediate…

πŸ“… Published: Oct. 30, 2024, midnight πŸ”„ Last Modified: Nov. 1, 2024, 12:57 p.m.

8

CVSS3.1

CVE-2024-48093 -

Unrestricted File Upload in the Discussions tab in Operately v.0.1.0 allows a privileged user to achieve Remote Code Execution via uploading and executing malicious files without validating file extensions or content types.

πŸ“… Published: Oct. 30, 2024, midnight πŸ”„ Last Modified: Nov. 1, 2024, 12:57 p.m.

8.8

CVSS3.1

CVE-2024-51304 -

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the ldap_search_dn function.

πŸ“… Published: Oct. 30, 2024, midnight πŸ”„ Last Modified: April 10, 2025, 3:52 p.m.

8.8

CVSS3.1

CVE-2024-51425 -

An issue in the WaterToken smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact. NOTE: this is disputed by third parties because the impact is limited to function calls.

πŸ“… Published: Oct. 30, 2024, midnight πŸ”„ Last Modified: Nov. 4, 2024, 6:15 a.m.

5.4

CVSS3.1

CVE-2024-50348 - InstantCMS has a Cross Site Scripting Vulnerability

InstantCMS is a free and open source content management system. In photo upload function in the photo album page there is no input validation taking place. Due to this attackers are able to inject the XSS (Cross Site Scripting) payload and execute. This vulnerability is fixed in 2.16.3.

πŸ“… Published: Oct. 29, 2024, 10:25 p.m. πŸ”„ Last Modified: Nov. 6, 2024, 2:49 p.m.

8.8

CVSS3.1

CVE-2024-10488 -

Use after free in WebRTC in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: Oct. 29, 2024, 9:55 p.m. πŸ”„ Last Modified: Jan. 2, 2025, 6:08 p.m.

8.8

CVSS3.1

CVE-2024-10487 -

Out of bounds write in Dawn in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical)

πŸ“… Published: Oct. 29, 2024, 9:55 p.m. πŸ”„ Last Modified: Jan. 2, 2025, 6:08 p.m.

7.8

CVSS3.1

CVE-2024-7992 - Autodesk AutoCAD DWG Stack-Based Buffer Overflow Code Execution Vulnerability

A maliciously crafted DWG file, when parsed through Autodesk AutoCAD and certain AutoCAD-based products, can force a Stack-based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

πŸ“… Published: Oct. 29, 2024, 9:50 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 6:24 p.m.

7.8

CVSS3.1

CVE-2024-7991 - Autodesk AutoCAD DWG Out-of-Bounds Write Code Execution Vulnerability

A maliciously crafted DWG file, when parsed through Autodesk AutoCAD and certain AutoCAD-based products, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current…

πŸ“… Published: Oct. 29, 2024, 9:49 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 6:23 p.m.

7.8

CVSS3.1

CVE-2024-9997 - Autodesk AutoCAD DWG File Parsing Memory Corruption Code Execution Vulnerability

A maliciously crafted DWG file when parsed in acdb25.dll through Autodesk AutoCAD can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.

πŸ“… Published: Oct. 29, 2024, 9:45 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 6:41 p.m.
Total resulsts: 344126
Page 7584 of 34,413
Β« previous page Β» next page
Filters