8.8

CVSS3.1

CVE-2024-26273 -

Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.4.0 through 7.4.3.103, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92 and 7.3 update 29 through update 35 allows remote attackers to (1) change user pas…

πŸ“… Published: Oct. 22, 2024, 3:01 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 3:55 a.m.

5.9

CVSS3.1

CVE-2024-43177 - IBM Concert improper certificate validation

IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.

πŸ“… Published: Oct. 22, 2024, 2:52 p.m. πŸ”„ Last Modified: Oct. 25, 2024, 4:05 p.m.

8.8

CVSS3.1

CVE-2024-26272 -

Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.3.2 through 7.4.3.107, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92 and 7.3 GA through update 35 allows remote attackers to (1) change user passwords,…

πŸ“… Published: Oct. 22, 2024, 2:50 p.m. πŸ”„ Last Modified: Dec. 10, 2024, 9:07 p.m.

3.7

CVSS3.1

CVE-2024-43173 - IBM Concert information disclosure

IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.

πŸ“… Published: Oct. 22, 2024, 2:48 p.m. πŸ”„ Last Modified: Oct. 25, 2024, 3:40 p.m.

9.6

CVSS3.1

CVE-2024-8980 -

The Script Console in Liferay Portal 7.0.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, 7.2 GA through fix pack 20, 7.1 GA through fix pack 28, 7.0 GA through fix pack 102 and 6.2 GA through fix pack 173 does not sufficiently p…

πŸ“… Published: Oct. 22, 2024, 2:43 p.m. πŸ”„ Last Modified: Dec. 10, 2024, 9:07 p.m.

8.8

CVSS3.1

CVE-2024-26271 -

Cross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3.75 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 update 75 through update 92 and 7.3 update 32 through update 36 allows remote attackers to (1) change …

πŸ“… Published: Oct. 22, 2024, 2:06 p.m. πŸ”„ Last Modified: Dec. 10, 2024, 9:07 p.m.

7.8

CVSS3.1

CVE-2024-9050 - Networkmanager-libreswan: local privilege escalation via leftupdown

A flaw was found in the libreswan client plugin for NetworkManager (NetkworkManager-libreswan), where it fails to properly sanitize the VPN configuration from the local unprivileged user. In this configuration, composed by a key-value format, the plugin fails to escape special characters, leading t…

πŸ“… Published: Oct. 22, 2024, noon πŸ”„ Last Modified: Nov. 20, 2025, 7:34 a.m.

0.0

CVE-2024-10246 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: Oct. 22, 2024, 11:30 a.m. πŸ”„ Last Modified: Sept. 20, 2025, 10:19 p.m.

0.0

CVE-2024-10243 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: Oct. 22, 2024, 10:02 a.m. πŸ”„ Last Modified: July 5, 2025, 11:15 p.m.

6.4

CVSS3.1

CVE-2024-10189 - Anchor Episodes Index (Spotify for Podcasters) <= 2.1.10 - Authenticated (Contributor+) Stored Cros…

The Anchor Episodes Index (Spotify for Podcasters) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's anchor_episodes shortcode in all versions up to, and including, 2.1.10 due to insufficient input sanitization and output escaping on user supplied attributes. This m…

πŸ“… Published: Oct. 22, 2024, 9:32 a.m. πŸ”„ Last Modified: April 8, 2026, 5:06 p.m.
Total resulsts: 343921
Page 7651 of 34,393
Β« previous page Β» next page
Filters