6.1

CVSS3.1

CVE-2024-10234 - Wildfly: wildfly vulnerable to cross-site scripting (xss)

A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system. This flaw allows an attacker or insider to execute a deployment with a malicious payload, which could trigger undesired behavior against the server.

πŸ“… Published: Oct. 22, 2024, midnight πŸ”„ Last Modified: Nov. 11, 2025, 4:05 p.m.

6.1

CVSS3.1

CVE-2022-23861 -

Multiple Stored Cross-Site Scripting vulnerabilities were discovered in Y Soft SAFEQ 6 Build 53. Multiple fields in the YSoft SafeQ web application can be used to inject malicious inputs that, due to a lack of output sanitization, result in the execution of arbitrary JS code. These fields can be le…

πŸ“… Published: Oct. 22, 2024, midnight πŸ”„ Last Modified: Nov. 1, 2024, 2:19 p.m.

4.6

CVSS3.1

CVE-2024-48415 -

itsourcecode Loan Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the lastname, firstname, middlename, address, contact_no, email and tax_id parameters in new borrowers functionality on the Borrowers page.

πŸ“… Published: Oct. 22, 2024, midnight πŸ”„ Last Modified: Nov. 26, 2024, 8:29 p.m.

5.3

CVSS3.1

CVE-2024-40493 -

Null Pointer Dereference in `coap_client_exchange_blockwise2` function in Keith Cullen FreeCoAP 1.0 allows remote attackers to cause a denial of service and potentially execute arbitrary code via a specially crafted CoAP packet that causes `coap_msg_get_payload(resp)` to return a null pointer, whic…

πŸ“… Published: Oct. 22, 2024, midnight πŸ”„ Last Modified: Oct. 25, 2024, 5:01 p.m.

6.5

CVSS3.1

CVE-2024-49209 -

Archer Platform 2024.03 before version 2024.09 is affected by an API authorization bypass vulnerability related to supporting application files. A remote unprivileged attacker could potentially exploit this vulnerability to elevate their privileges and upload additional system icons.

πŸ“… Published: Oct. 22, 2024, midnight πŸ”„ Last Modified: March 14, 2025, 4:15 p.m.

7.5

CVSS3.1

CVE-2024-44331 - gstreamer1-rtsp-server: DoS via rtsp-media.c

Incorrect Access Control in GStreamer RTSP server 1.25.0 in gst-rtsp-server/rtsp-media.c allows remote attackers to cause a denial of service via a series of specially crafted hexstream requests.

πŸ“… Published: Oct. 22, 2024, midnight πŸ”„ Last Modified: Oct. 23, 2024, 6:35 p.m.

8.1

CVSS3.1

CVE-2024-48657 -

SQL Injection vulnerability in hospital management system in php with source code v.1.0.0 allows a remote attacker to execute arbitrary code.

πŸ“… Published: Oct. 22, 2024, midnight πŸ”„ Last Modified: Oct. 24, 2024, 2:38 p.m.

9.8

CVSS3.1

CVE-2024-44812 -

SQL Injection vulnerability in Online Complaint Site v.1.0 allows a remote attacker to escalate privileges via the username and password parameters in the /admin.index.php component.

πŸ“… Published: Oct. 22, 2024, midnight πŸ”„ Last Modified: Oct. 25, 2024, 4:56 p.m.

5.3

CVSS3.1

CVE-2024-48644 -

Accounts enumeration vulnerability in the Login Component of Reolink Duo 2 WiFi Camera (Firmware Version v3.0.0.1889_23031701) allows remote attackers to determine valid user accounts via login attempts. This can lead to the enumeration of user accounts and potentially facilitate other attacks, suc…

πŸ“… Published: Oct. 22, 2024, midnight πŸ”„ Last Modified: Oct. 23, 2024, 7:35 p.m.

5.5

CVSS3.1

CVE-2023-52919 - nfc: nci: fix possible NULL pointer dereference in send_acknowledge()

In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix possible NULL pointer dereference in send_acknowledge() Handle memory allocation failure from nci_skb_alloc() (calling alloc_skb()) to avoid possible NULL pointer dereference.

πŸ“… Published: Oct. 22, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 7:45 a.m.
Total resulsts: 343923
Page 7655 of 34,393
Β« previous page Β» next page
Filters