5.4

CVSS3.1

CVE-2024-51026 -

The NetAdmin IAM system (version 4.0.30319) has a Cross Site Scripting (XSS) vulnerability in the /BalloonSave.ashx endpoint, where it is possible to inject a malicious payload into the Content= field.

πŸ“… Published: Nov. 11, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2024-11079 - Ansible-core: unsafe tagging bypass via hostvars object in ansible-core

A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module outputs are improperly templated within playbooks.

πŸ“… Published: Nov. 11, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2024-46962 -

The SYQ com.downloader.video.fast (aka Master Video Downloader) application through 2.0 for Android allows an attacker to execute arbitrary JavaScript code via the com.downloader.video.fast.SpeedMainAct component.

πŸ“… Published: Nov. 11, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-52531 - libsoup: buffer overflow via UTF-8 conversion in soup_header_parse_param_list_strict

GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict. There is a plausible way to reach this remotely via soup_message_headers_get_content_type (e.g., an application may want to retrieve the content type of a req…

πŸ“… Published: Nov. 11, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:17 p.m.

4.8

CVSS3.1

CVE-2024-51190 -

TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the ptRule_ApplicationName_1.1.6.0.0 parameter on the /special_ap.htm page.

πŸ“… Published: Nov. 11, 2024, midnight πŸ”„ Last Modified: April 1, 2025, 6:21 p.m.

6.1

CVSS3.1

CVE-2024-50601 -

Persistent and reflected XSS vulnerabilities in the themeMode cookie and _h URL parameter of Axigen Mail Server up to version 10.5.28 allow attackers to execute arbitrary Javascript. Exploitation could lead to session hijacking, data leakage, and further exploitation via a multi-stage attack. Fixed…

πŸ“… Published: Nov. 11, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-49393 - Mutt: neomutt: to and cc email header fields are not protected by cryptographic signing

In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compromise message confidentiality.

πŸ“… Published: Nov. 11, 2024, midnight πŸ”„ Last Modified: Nov. 20, 2025, 7:20 p.m.

9.8

CVSS3.1

CVE-2024-50667 -

The boa httpd of Trendnet TEW-820AP 1.01.B01 has a stack overflow vulnerability in /boafrm/formIPv6Addr, /boafrm/formIpv6Setup, /boafrm/formDnsv6. The reason is that the check of ipv6 address is not sufficient, which allows attackers to construct payloads for attacks.

πŸ“… Published: Nov. 11, 2024, midnight πŸ”„ Last Modified: April 1, 2025, 6:21 p.m.

7.5

CVSS3.1

CVE-2024-52532 - libsoup: infinite loop while reading websocket data

GNOME libsoup before 3.6.1 has an infinite loop, and memory consumption. during the reading of certain patterns of WebSocket data from clients.

πŸ“… Published: Nov. 11, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:17 p.m.

6.1

CVSS3.1

CVE-2024-51213 -

Cross Site Scripting vulnerability in Online Shop Store v.1.0 allows a remote attacker to execute arbitrary code via the login.php component.

πŸ“… Published: Nov. 11, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347406
Page 7774 of 34,741
Β« previous page Β» next page
Filters