5.3

CVSS4.0

CVE-2024-10379 - ESAFENET CDG DecryptApplicationService.java actionViewDecyptFile path traversal

A vulnerability classified as problematic was found in ESAFENET CDG 5. Affected by this vulnerability is the function actionViewDecyptFile of the file /com/esafenet/servlet/client/DecryptApplicationService.java. The manipulation of the argument decryptFileId with the input ../../../Windows/System32…

πŸ“… Published: Oct. 25, 2024, noon πŸ”„ Last Modified: Oct. 30, 2024, 6:54 p.m.

5.3

CVSS4.0

CVE-2024-10378 - ESAFENET CDG CDGRenewApplicationService.java actionViewCDGRenewFile sql injection

A vulnerability classified as critical has been found in ESAFENET CDG 5. Affected is the function actionViewCDGRenewFile of the file /com/esafenet/servlet/client/CDGRenewApplicationService.java. The manipulation of the argument CDGRenewFileId leads to sql injection. It is possible to launch the att…

πŸ“… Published: Oct. 25, 2024, noon πŸ”„ Last Modified: Oct. 30, 2024, 11:58 p.m.

6.4

CVSS3.1

CVE-2024-10374 - WP-Members <= 3.4.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpmem_loginout…

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpmem_loginout shortcode in all versions up to, and including, 3.4.9.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible f…

πŸ“… Published: Oct. 25, 2024, 11:36 a.m. πŸ”„ Last Modified: April 8, 2026, 4:56 p.m.

5.3

CVSS4.0

CVE-2024-10377 - ESAFENET CDG DecryptApplicationService.java actionPassDecryptApplication1 sql injection

A vulnerability was found in ESAFENET CDG 5. It has been rated as critical. This issue affects the function actionPassDecryptApplication1 of the file /com/esafenet/servlet/client/DecryptApplicationService.java. The manipulation of the argument id leads to sql injection. The attack may be initiated …

πŸ“… Published: Oct. 25, 2024, 11 a.m. πŸ”„ Last Modified: Nov. 5, 2024, 7:41 p.m.

5.3

CVSS4.0

CVE-2024-10376 - ESAFENET CDG AutoSignService.java actionPassOrNotAutoSign sql injection

A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. This vulnerability affects the function actionPassOrNotAutoSign of the file /com/esafenet/servlet/service/processsign/AutoSignService.java. The manipulation of the argument UniqueId leads to sql injection. The attack can…

πŸ“… Published: Oct. 25, 2024, 11 a.m. πŸ”„ Last Modified: Nov. 5, 2024, 7:41 p.m.

2.9

CVSS3.1

CVE-2024-47483 -

Dell Data Lakehouse, version(s) 1.0.0.0 and 1.1.0.0, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.

πŸ“… Published: Oct. 25, 2024, 10:59 a.m. πŸ”„ Last Modified: Oct. 31, 2024, 12:01 a.m.

6.5

CVSS3.1

CVE-2024-47481 -

Dell Data Lakehouse, version(s) 1.0.0.0, 1.1.0., contain(s) an Improper Access Control vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Denial of service.

πŸ“… Published: Oct. 25, 2024, 10:54 a.m. πŸ”„ Last Modified: Oct. 31, 2024, 12:01 a.m.

7.4

CVSS3.1

CVE-2024-47041 -

In valid_address of syscall.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

πŸ“… Published: Oct. 25, 2024, 10:34 a.m. πŸ”„ Last Modified: Nov. 4, 2024, 10:16 p.m.

7.4

CVSS3.1

CVE-2024-47035 -

In vring_init of external/headers/include/virtio/virtio_ring.h, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

πŸ“… Published: Oct. 25, 2024, 10:34 a.m. πŸ”„ Last Modified: Oct. 31, 2024, 12:05 a.m.

5.1

CVSS3.1

CVE-2024-47034 -

there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

πŸ“… Published: Oct. 25, 2024, 10:34 a.m. πŸ”„ Last Modified: Oct. 28, 2024, 5:56 p.m.
Total resulsts: 343923
Page 7614 of 34,393
Β« previous page Β» next page
Filters