7.5

CVSS3.1

CVE-2024-11187 - Many records in the additional section cause CPU exhaustion

It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section. An attacker sending many such queries can cause either the authoritative server itself or an independent resolver to use disproportionate resources processi…

πŸ“… Published: Jan. 29, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-57513 -

A floating-point exception (FPE) vulnerability exists in the AP4_TfraAtom::AP4_TfraAtom function in Bento4.

πŸ“… Published: Jan. 29, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2024-57510 -

Buffer Overflow vulnerability in Bento4 mp42avc v.3bdc891602d19789b8e8626e4a3e613a937b4d35 allows a local attacker to execute arbitrary code via the AP4_MemoryByteStream::WritePartial.

πŸ“… Published: Jan. 29, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-57437 -

RuoYi v4.8.0 was discovered to contain a SQL injection vulnerability via the orderby parameter at /monitor/online/list.

πŸ“… Published: Jan. 29, 2025, midnight πŸ”„ Last Modified: May 14, 2025, 6:26 p.m.

8

CVSS3.1

CVE-2025-24527 -

An issue was discovered in Akamai Enterprise Application Access (EAA) before 2025-01-17. If an admin knows another tenant's 128-bit connector GUID, they can execute debug commands on that connector.

πŸ“… Published: Jan. 29, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-54851 -

Teedy <= 1.12 is vulnerable to Cross Site Request Forgery (CSRF), due to the lack of CSRF protection.

πŸ“… Published: Jan. 29, 2025, midnight πŸ”„ Last Modified: May 23, 2025, 3:23 p.m.

7.5

CVSS3.1

CVE-2024-23733 -

The /WmAdmin/,/invoke/vm.server/login login page in the Integration Server in Software AG webMethods 10.15.0 before Core_Fix7 allows remote attackers to reach the administration panel and discover hostname and version information by sending an arbitrary username and a blank password to the /WmAdmin…

πŸ“… Published: Jan. 29, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-54852 -

When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnerable to LDAP injection. Due to improper sanitization of user input, an unauthenticated attacker is then able to perform various malicious actions, such as creating arbitrary accoun…

πŸ“… Published: Jan. 29, 2025, midnight πŸ”„ Last Modified: May 24, 2025, 1:14 a.m.

9.8

CVSS3.1

CVE-2024-57665 -

JFinalCMS 1.0 is vulnerable to SQL Injection in rc/main/java/com/cms/entity/Content.java. The cause of the vulnerability is that the title parameter is controllable and is concatenated directly into filterSql without filtering.

πŸ“… Published: Jan. 29, 2025, midnight πŸ”„ Last Modified: May 23, 2025, 2:50 p.m.

4.9

CVSS3.1

CVE-2024-57439 -

An issue in the reset password interface of ruoyi v4.8.0 allows attackers with Admin privileges to cause a Denial of Service (DoS) by duplicating the login name of the account.

πŸ“… Published: Jan. 29, 2025, midnight πŸ”„ Last Modified: May 14, 2025, 6:26 p.m.
Total resulsts: 347742
Page 6777 of 34,775
Β« previous page Β» next page
Filters