6.5

CVSS3.1

CVE-2024-7137 - Denial of Service in Silicon Labs RS9116 Bluetooth SDK

The L2CAP receive data buffer for L2CAP packets is restricted to packet sizes smaller than the maximum supported packet size. Receiving a packet that exceeds the restricted buffer length may cause a crash. A hard reset is required to recover the crashed device.

๐Ÿ“… Published: Dec. 19, 2024, 7:23 p.m. ๐Ÿ”„ Last Modified: May 28, 2025, 2:15 p.m.

5.3

CVSS3.1

CVE-2024-49765 - Bypass of Discourse Connect using other login paths if enabled in Discourse

Discourse is an open source platform for community discussion. Sites that are using discourse connect but still have local logins enabled could allow attackers to bypass discourse connect to create accounts and login. This problem is patched in the latest version of Discourse. Users unable to upgraโ€ฆ

๐Ÿ“… Published: Dec. 19, 2024, 7:15 p.m. ๐Ÿ”„ Last Modified: Sept. 26, 2025, 12:50 p.m.

2.2

CVSS3.1

CVE-2024-52589 - Moderators can view Screened emails even when the โ€œmoderators view emailsโ€ option is disabled in Diโ€ฆ

Discourse is an open source platform for community discussion. Moderators can see the Screened emails list in the admin dashboard, and through that can learn the email of a user. This problem is patched in the latest version of Discourse. Users unable to upgrade should remove moderator role from unโ€ฆ

๐Ÿ“… Published: Dec. 19, 2024, 7:13 p.m. ๐Ÿ”„ Last Modified: Aug. 26, 2025, 2:16 a.m.

6.8

CVSS3.1

CVE-2024-52794 - Magnific lightbox susceptible to Cross-site Scripting in Discourse

Discourse is an open source platform for community discussion. Users clicking on the lightbox thumbnails could be affected. This problem is patched in the latest version of Discourse. Users are advised to upgrade. There are no known workarounds for this vulnerability.

๐Ÿ“… Published: Dec. 19, 2024, 7:12 p.m. ๐Ÿ”„ Last Modified: Aug. 26, 2025, 2:14 a.m.

7.5

CVSS3.1

CVE-2024-53991 - Potential Backup file leaked via Nginx in Discourse

Discourse is an open source platform for community discussion. This vulnerability only impacts Discourse instances configured to use `FileStore::LocalStore` which means uploads and backups are stored locally on disk. If an attacker knows the name of the Discourse backup file, the attacker can trickโ€ฆ

๐Ÿ“… Published: Dec. 19, 2024, 7:11 p.m. ๐Ÿ”„ Last Modified: Aug. 26, 2025, 2:02 a.m.

7.8

CVSS4.0

CVE-2024-56159 - Server source code is exposed to the public if sourcemaps are enabled

Astro is a web framework for content-driven websites. A bug in the build process allows any unauthenticated user to read parts of the server source code. During build, along with client assets such as css and font files, the sourcemap files **for the server code** are moved to a publicly-accessibleโ€ฆ

๐Ÿ“… Published: Dec. 19, 2024, 6:58 p.m. ๐Ÿ”„ Last Modified: Nov. 25, 2025, 1:38 p.m.

8.6

CVSS3.1

CVE-2024-56200 - Uncontrolled Recursion and Asymmetric Resource Consumption in Altair media/file proxy

Altair is a fork of Misskey v12. Affected versions lack of request validation and lack of authentication in the image proxy for compressing and resizing remote files could allow attacks that could affect availability, such as by abnormally increasing the CPU usage of the server on which this softwaโ€ฆ

๐Ÿ“… Published: Dec. 19, 2024, 6:43 p.m. ๐Ÿ”„ Last Modified: Dec. 20, 2024, 8:03 p.m.

8.7

CVSS4.0

CVE-2024-54150 - Algorithm Confusion Vulnerability in cjwt

cjwt is a C JSON Web Token (JWT) Implementation. Algorithm confusion occurs when a system improperly verifies the type of signature used, allowing attackers to exploit the lack of distinction between signing methods. If the system doesn't differentiate between an HMAC signed token and an RS/EC/PS โ€ฆ

๐Ÿ“… Published: Dec. 19, 2024, 6:22 p.m. ๐Ÿ”„ Last Modified: Dec. 20, 2024, 6:15 p.m.

5.7

CVSS3.1

CVE-2020-6923 - HP Linux Imaging and Printing Software - Potential Memory Buffer Overflow

The HP Linux Imaging and Printing (HPLIP) software may potentially be affected by memory buffer overflow.

๐Ÿ“… Published: Dec. 19, 2024, 6:16 p.m. ๐Ÿ”„ Last Modified: Dec. 20, 2024, 5:38 p.m.

5.3

CVSS4.0

CVE-2024-12794 - Codezips E-Commerce Site editorder.php sql injection

A vulnerability, which was classified as critical, was found in Codezips E-Commerce Site 1.0. This affects an unknown part of the file /admin/editorder.php. The manipulation of the argument dstatus/quantity/ddate leads to sql injection. It is possible to initiate the attack remotely. The exploit haโ€ฆ

๐Ÿ“… Published: Dec. 19, 2024, 6 p.m. ๐Ÿ”„ Last Modified: Jan. 6, 2025, 2:40 p.m.
Total resulsts: 343980
Page 6888 of 34,398
ยซ previous page ยป next page
Filters