6.4

CVSS3.1

CVE-2024-0334 - Jeg Elementor Kit <= 2.6.4 - Authenticated (Contributor+) Cross-Site Scripting via Elementor Widget…

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom attribute of a link in several Elementor widgets in all versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it p…

πŸ“… Published: May 1, 2024, 12:46 p.m. πŸ”„ Last Modified: April 8, 2026, 5:09 p.m.

7.5

CVSS3.1

CVE-2024-32979 - Reflected Cross-site Scripting potential in all object list views in Nautobot

Nautobot is a Network Source of Truth and Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database. It was discovered that due to improper handling and escaping of user-provided query parameters, a maliciously crafted Nautobot URL c…

πŸ“… Published: May 1, 2024, 10:49 a.m. πŸ”„ Last Modified: Aug. 26, 2025, 6:54 p.m.

7.5

CVSS3.1

CVE-2024-32984 - Yamux Memory Exhaustion Vulnerability via Active::pending_frames property

Yamux is a stream multiplexer over reliable, ordered connections such as TCP/IP. The Rust implementation of the Yamux stream multiplexer uses a vector for pending frames. This vector is not bounded in length. Every time the Yamux protocol requires sending of a new frame, this frame gets appended to…

πŸ“… Published: May 1, 2024, 10:45 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS3.1

CVE-2024-32973 - Remote for TLS session may be trusted despite constraints in Pluto lang

Pluto is a superset of Lua 5.4 with a focus on general-purpose programming. In affected versions an attacker with the ability to actively intercept network traffic would be able to use a specifically-crafted certificate to fool Pluto into trusting it to be the intended remote for the TLS session. T…

πŸ“… Published: May 1, 2024, 10:42 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-32967 - Zitadel exposes internal database user name and host information

Zitadel is an open source identity management system. In case ZITADEL could not connect to the database, connection information including db name, username and db host name could be returned to the user. This has been addressed in all supported release branches in a point release. There is no worka…

πŸ“… Published: May 1, 2024, 6:43 a.m. πŸ”„ Last Modified: Jan. 8, 2025, 6:30 p.m.

4.2

CVSS3.1

CVE-2024-32963 - Parameter Tampering vulnerability in Navidrome

Navidrome is an open source web-based music collection server and streamer. In affected versions of Navidrome are subject to a parameter tampering vulnerability where an attacker has the ability to manipulate parameter values in the HTTP requests. The attacker is able to change the parameter values…

πŸ“… Published: May 1, 2024, 6:39 a.m. πŸ”„ Last Modified: Aug. 26, 2025, 6:52 p.m.

6.1

CVSS3.1

CVE-2024-32890 - Stored Cross-site Scripting in results JSON API in librespeed/speedtest

librespeed/speedtest is an open source, self-hosted speed test for HTML5. In affected versions missing neutralization of the ISP information in a speedtest result leads to stored Cross-site scripting in the JSON API. The `processedString` field in the `ispinfo` parameter is missing neutralization. …

πŸ“… Published: May 1, 2024, 6:34 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.7

CVSS3.1

CVE-2024-23335 - Backups directory .htaccess deletion in. MyBB

MyBB is a free and open source forum software. The backup management module of the Admin CP may accept `.htaccess` as the name of the backup file to be deleted, which may expose the stored backup files over HTTP on Apache servers. MyBB 1.8.38 resolves this issue. Users are advised to upgrade. There…

πŸ“… Published: May 1, 2024, 6:27 a.m. πŸ”„ Last Modified: June 30, 2025, 3:03 p.m.

5

CVSS3.1

CVE-2024-23336 - Incomplete disallowed remote addresses list in MyBB

MyBB is a free and open source forum software. The default list of disallowed remote hosts does not contain the `127.0.0.0/8` block, which may result in a Server-Side Request Forgery (SSRF) vulnerability. The Configuration File's _Disallowed Remote Addresses_ list (`$config['disallowed_remote_addre…

πŸ“… Published: May 1, 2024, 6:27 a.m. πŸ”„ Last Modified: June 30, 2025, 3:10 p.m.

8.8

CVSS3.1

CVE-2024-32018 - Ineffective size check due to assert() and buffer overflow in RIOT

RIOT is a real-time multi-threading operating system that supports a range of devices that are typically 8-bit, 16-bit and 32-bit microcontrollers. Most codebases define assertion macros which compile to a no-op on non-debug builds. If assertions are the only line of defense against untrusted input…

πŸ“… Published: May 1, 2024, 6:14 a.m. πŸ”„ Last Modified: Sept. 5, 2025, 1:17 p.m.
Total resulsts: 349182
Page 10099 of 34,919
Β« previous page Β» next page
Filters