0.0

CVE-2024-10391 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

๐Ÿ“… Published: Oct. 25, 2024, 3:30 p.m. ๐Ÿ”„ Last Modified: July 9, 2025, 10:15 p.m.

7.5

CVSS3.1

CVE-2024-49757 - Zitadel User Registration Bypass Vulnerability

The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. Due to a missing security check in versions prior to 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, and 2.58.7, disabling the "User Registration allowed" option only hid the registโ€ฆ

๐Ÿ“… Published: Oct. 25, 2024, 2:22 p.m. ๐Ÿ”„ Last Modified: Aug. 26, 2025, 4:31 p.m.

5.9

CVSS3.1

CVE-2024-49753 - Denied Host Validation Bypass in Zitadel Actions

Zitadel is open-source identity infrastructure software. Versions prior to 2.64.1, 2.63.6, 2.62.8, 2.61.4, 2.60.4, 2.59.5, and 2.58.7 have a flaw in the URL validation mechanism of Zitadel actions allows bypassing restrictions intended to block requests to localhost (127.0.0.1). The isHostBlocked cโ€ฆ

๐Ÿ“… Published: Oct. 25, 2024, 2:11 p.m. ๐Ÿ”„ Last Modified: Aug. 26, 2025, 4:28 p.m.

7.7

CVSS4.0

CVE-2024-49381 - Plenti arbitrary file deletion vulnerability

Plenti, a static site generator, has an arbitrary file deletion vulnerability in versions prior to 0.7.2. The `/postLocal` endpoint is vulnerable to an arbitrary file write deletion when a plenti user serves their website. This issue may lead to information loss. Version 0.7.2 fixes the vulnerabiliโ€ฆ

๐Ÿ“… Published: Oct. 25, 2024, 1:06 p.m. ๐Ÿ”„ Last Modified: Nov. 14, 2024, 11:04 p.m.

8.9

CVSS4.0

CVE-2024-49380 - Plenti arbitrary file write vulnerability

Plenti, a static site generator, has an arbitrary file write vulnerability in versions prior to 0.7.2. The `/postLocal` endpoint is vulnerable to an arbitrary file write vulnerability when a plenti user serves their website. This issue may lead to Remote Code Execution. Version 0.7.2 fixes the vulnโ€ฆ

๐Ÿ“… Published: Oct. 25, 2024, 1:04 p.m. ๐Ÿ”„ Last Modified: May 6, 2025, 5:53 p.m.

5.3

CVSS4.0

CVE-2024-10380 - SourceCodester Petrol Pump Management Software ajax_product.php sql injection

A vulnerability, which was classified as critical, has been found in SourceCodester Petrol Pump Management Software 1.0. Affected by this issue is some unknown functionality of the file /admin/ajax_product.php. The manipulation of the argument drop_services leads to sql injection. The attack may beโ€ฆ

๐Ÿ“… Published: Oct. 25, 2024, 1 p.m. ๐Ÿ”„ Last Modified: Nov. 1, 2024, 4:11 p.m.

5.8

CVSS4.0

CVE-2024-49378 - smartUp Cross-site Scripting vulnerability

smartUp, a web browser mouse gestures extension, has a universal cross-site scripting issue in the Edge and Firefox versions of smartUp 7.2.622.1170. The vulnerability allows another extension to execute arbitrary code in the context of the userโ€™s tab. As of time of publication, no known patches exโ€ฆ

๐Ÿ“… Published: Oct. 25, 2024, 12:55 p.m. ๐Ÿ”„ Last Modified: Oct. 28, 2024, 1:58 p.m.

7.1

CVSS4.0

CVE-2024-49376 - Autolab Has Misconfigured Reset Password Permissions

Autolab, a course management service that enables auto-graded programming assignments, has misconfigured reset password permissions in version 3.0.0. For email-based accounts, users with insufficient privileges could reset and theoretically access privileged users' accounts by resetting their passwโ€ฆ

๐Ÿ“… Published: Oct. 25, 2024, 12:50 p.m. ๐Ÿ”„ Last Modified: Nov. 14, 2024, 10:49 p.m.

9.3

CVSS4.0

CVE-2024-10381 - Authentication Bypass Vulnerability in Matrix Door Controller

This vulnerability exists in Matrix Door Controller Cosec Vega FAXQ due to improper implementation of session management at the web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http request on the vulnerable device. Successful exploiโ€ฆ

๐Ÿ“… Published: Oct. 25, 2024, 12:36 p.m. ๐Ÿ”„ Last Modified: Nov. 14, 2024, 9:44 p.m.

7

CVSS4.0

CVE-2024-9991 - Cleartext Storage of Sensitive Information Vulnerability in Philips Lighting Devices

This vulnerability exists in Philips lighting devices due to storage of Wi-Fi credentials in plain text within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obtain the plaintext Wi-Fi credentials stored on the vuโ€ฆ

๐Ÿ“… Published: Oct. 25, 2024, 12:27 p.m. ๐Ÿ”„ Last Modified: Oct. 28, 2024, 1:58 p.m.
Total resulsts: 343923
Page 7613 of 34,393
ยซ previous page ยป next page
Filters