8.6

CVSS3.1

CVE-2024-25047 - IBM Cognos Analytics log injection

IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.2 is vulnerable to injection attacks in application logging by not sanitizing user provided data. This could lead to further attacks against the system. IBM X-Force ID: 282956.

πŸ“… Published: May 2, 2024, 8:09 p.m. πŸ”„ Last Modified: July 2, 2025, 3:41 p.m.

7.5

CVSS3.1

CVE-2024-4140 -

An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1.954, which can cause denial of service when parsing multipart MIME messages. The patch set (from 2020 and 2024) limits excessive depth and the total number of parts.

πŸ“… Published: May 2, 2024, 7:59 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 5:21 p.m.

8.1

CVSS3.1

CVE-2024-34394 - libxmljs2 namespaces type confusion RCE

libxmljs2 is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking the namespaces() function (which invokes XmlNode::get_local_namespaces()) on a grand-child of a node that refers to an entity. This vulnerability can lead to denial of service and remote co…

πŸ“… Published: May 2, 2024, 6:57 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2024-34393 - libxmljs2 attrs type confusion RCE

libxmljs2 is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking a function on the result of attrs() that was called on a parsed node. This vulnerability might lead to denial of service (on both 32-bit systems and 64-bit systems), data leak, infinite loo…

πŸ“… Published: May 2, 2024, 6:56 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2024-34392 - libxmljs namespaces type confusion RCE

libxmljs is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking the namespaces() function (which invokes _wrap__xmlNode_nsDef_get()) on a grand-child of a node that refers to an entity. This vulnerability can lead to denial of service and remote code exe…

πŸ“… Published: May 2, 2024, 6:55 p.m. πŸ”„ Last Modified: Oct. 10, 2025, 6:19 p.m.

8.1

CVSS3.1

CVE-2024-34391 - libxmljs attrs type confusion RCE

libxmljs is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking a function on the result of attrs() that was called on a parsed node. This vulnerability might lead to denial of service (on both 32-bit systems and 64-bit systems), data leak, infinite loop…

πŸ“… Published: May 2, 2024, 6:54 p.m. πŸ”„ Last Modified: Oct. 10, 2025, 6:20 p.m.

7.4

CVSS3.1

CVE-2024-4216 - XSS vulnerability in /settings/store API response json payload in pgAdmin 4

pgAdmin <= 8.5 is affected by XSS vulnerability in /settings/store API response json payload. This vulnerability allows attackers to execute malicious script at the client end.

πŸ“… Published: May 2, 2024, 5:42 p.m. πŸ”„ Last Modified: Sept. 19, 2025, 1:27 p.m.

7.4

CVSS3.1

CVE-2024-4215 - The Multi Factor Authentication bypass vulnerability in pgAdmin 4

pgAdmin <= 8.5 is affected by a multi-factor authentication bypass vulnerability. This vulnerability allows an attacker with knowledge of a legitimate account’s username and password may authenticate to the application and perform sensitive actions within the application, such as managing files and…

πŸ“… Published: May 2, 2024, 5:42 p.m. πŸ”„ Last Modified: Sept. 19, 2025, 1:37 p.m.

6.1

CVSS3.1

CVE-2024-3681 - Interactive World Maps <= 2.4.14 - Reflected Cross-Site Scripting

The Interactive World Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search (s) parameter in all versions up to, and including, 2.4.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitr…

πŸ“… Published: May 2, 2024, 4:57 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-3473 - Header Footer Code Manager Pro <= 1.0.16 - Reflected Cross-Site Scripting via message

The Header Footer Code Manager Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the message parameter in all versions up to, and including, 1.0.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject a…

πŸ“… Published: May 2, 2024, 4:57 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 10071 of 34,919
Β« previous page Β» next page
Filters