6.5
CVE-2024-57723 -
lunasvg v3.0.0 was discovered to contain a segmentation violation via the component composition_source_over.
5.4
CVE-2024-57329 -
HortusFox v3.9 contains a stored XSS vulnerability in the "Add Plant" function. The name input field does not sanitize or escape user inputs, allowing attackers to inject and execute arbitrary JavaScript payloads.
5.5
CVE-2024-57947 - netfilter: nf_set_pipapo: fix initial map fill
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_set_pipapo: fix initial map fill The initial buffer has to be inited to all-ones, but it must restrict it to the size of the first field, not the total field size. After each round in the map search step, the resulβ¦
6.5
CVE-2024-57719 -
lunasvg v3.0.0 was discovered to contain a segmentation violation via the component blend_transformed_tiled_argb.isra.0.
6.5
CVE-2024-57720 -
lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_blend.
6.5
CVE-2024-57721 -
lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_path_add_path.
9.1
CVE-2024-55573 -
An issue was discovered in Centreon centreon-web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x before 23.04.24. A user with high privileges is able to inject SQL into the form used to create virtual metrics.
5.5
CVE-2024-50665 -
gpac 2.4 contains a SEGV at src/isomedia/drm_sample.c:1562:96 in isom_cenc_get_sai_by_saiz_saio in MP4Box.
4.3
CVE-2025-0754 - Envoyproxy: openshift service mesh 2.6.3 and 2.5.6 envoy header handling allows log injection and pβ¦
The vulnerability was found in OpenShift Service Mesh 2.6.3 and 2.5.6. This issue occurs due to improper sanitization of HTTP headers by Envoy, particularly the x-forwarded-for header. This lack of sanitization can allow attackers to inject malicious payloads into service mesh logs, leading to log β¦
6.4
CVE-2024-12477 - Avada Builder <= 3.11.11 - Authenticated (Contributor+) Stored Cross-Site Scripting in Multiple Widβ¦
The Avada Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.11.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, wβ¦