Known vulnerabilities in Web and Scripting Module - page 6

Vendor: SUSE
Software CPE: cpe:2.3:o:suse:web_and_scripting_module:*:*:*:*:*:*:*:*
Total vulnerabilities: 190
Public exploits: 17
Known exploited (KEV): 4
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Web and Scripting Module Web and Scripting Module is affected by 190 known vulnerabilities: 2 critical, 17 high, 126 medium, 45 low Critical High Medium Low

Vulnerabilities (190)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU100670 - Out-of-bounds read
CVE-2024-8932
CWE-125 Medium
No
No
- 19.11.2024 SB2024111985
SB2024112137
SB2024112138
and 11 more
#VU100588 - Improper Authentication
CVE-2024-52316
CWE-287 Low
No
No
- 18.11.2024 SB2024111823
SB2024112550
SB2024112832
and 36 more
#VU97748 - Improper input validation
CVE-2024-8925
CWE-20 Medium
No
No
- 27.09.2024 SB2024092724
SB2024100148
SB2024100301
and 16 more
#VU97747 - Insufficient Logging
CVE-2024-9026
CWE-778 Low
No
No
- 27.09.2024 SB2024092724
SB2024100148
SB2024101209
and 13 more
#VU97746 - Security Features
CVE-2024-8927
CWE-254 Medium
No
No
- 27.09.2024 SB2024092724
SB2024100148
SB2024100301
and 18 more
#VU96945 - Resource exhaustion
CVE-2024-7592
CWE-400 Medium
No
No
- 09.09.2024 SB2024090916
SB2024090917
SB2024090918
and 72 more
#VU96745 - Incorrect Regular Expression
CVE-2024-6232
CWE-185 Medium
No
No
- 03.09.2024 SB2024090377
SB2024090927
SB2024091048
and 145 more
#VU95571 - Command injection
CVE-2024-6923
CWE-77 Medium
No
No
- 08.08.2024 SB2024080861
SB2024080862
SB2024080863
and 144 more
#VU95157 - Incorrect Provision of Specified Functionality
CVE-2024-4032
CWE-684 Medium
No
No
- 02.08.2024 SB2024080203
SB2024080207
SB2024080209
and 101 more
#VU94852 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2024-41671
CWE-444 High
No
No
- 30.07.2024 SB2024073015
SB20240805108
SB20240806193
and 11 more
#VU94851 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-41810
CWE-79 Low
No
No
- 30.07.2024 SB2024073015
SB20240805108
SB20240806193
and 11 more
#VU93883 - Improper input validation
CVE-2024-37372
CWE-20 Low
No
No
- 09.07.2024 SB2024070937
SB20240717120
SB2024072232
and 7 more
#VU93882 - Permissions, Privileges, and Access Controls
CVE-2024-22018
CWE-264 Low
No
No
- 09.07.2024 SB2024070937
SB20240717120
SB2024072232
and 15 more
#VU93881 - Permissions, Privileges, and Access Controls
CVE-2024-36137
CWE-264 Low
No
No
- 09.07.2024 SB2024070937
SB20240717120
SB2024072232
and 23 more
#VU93880 - Server-Side Request Forgery (SSRF)
CVE-2024-22020
CWE-918 Medium
No
No
- 09.07.2024 SB2024070937
SB2024071636
SB20240717119
and 30 more
#VU93879 - Command injection
CVE-2024-36138
CWE-77 Medium
No
No
- 09.07.2024 SB2024070937
SB2024071636
SB20240717119
and 12 more
#VU93732 - Resource Management Errors
CVE-2024-34750
CWE-399 Medium
No
No
- 03.07.2024 SB2024070346
SB20240711245
SB2024071542
and 56 more
#VU91685 - Command injection
CVE-2024-35242
CWE-77 High
No
No
- 11.06.2024 SB2024061107
SB2024061108
SB2024061109
and 6 more
#VU91684 - Command injection
CVE-2024-35241
CWE-77 High
No
No
- 11.06.2024 SB2024061107
SB2024061108
SB2024061109
and 7 more
#VU88462 - Command injection
CVE-2024-27980
CWE-77 Medium
No
No
- 11.04.2024 SB2024041122
SB2024041155
SB2024041156
and 20 more


Showing elements 101 - 120 out of 190