7.5

CVSS3.1

CVE-2024-46982 - Cache Poisoning in next.js

Next.js is a React framework for building full-stack web applications. By sending a crafted HTTP request, it is possible to poison the cache of a non-dynamic server-side rendered route in the pages router (this does not affect the app router). When this crafted request is sent it could coerce Next.…

πŸ“… Published: Sept. 17, 2024, 9:55 p.m. πŸ”„ Last Modified: Sept. 10, 2025, 3:46 p.m.

4.3

CVSS3.1

CVE-2024-8909 -

Inappropriate implementation in UI in Google Chrome on iOS prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

πŸ“… Published: Sept. 17, 2024, 9:07 p.m. πŸ”„ Last Modified: March 17, 2025, 4:15 p.m.

4.3

CVSS3.1

CVE-2024-8908 -

Inappropriate implementation in Autofill in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

πŸ“… Published: Sept. 17, 2024, 9:07 p.m. πŸ”„ Last Modified: March 20, 2025, 9:15 p.m.

6.1

CVSS3.1

CVE-2024-8907 -

Insufficient data validation in Omnibox in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (XSS) via a crafted set of UI gestures. (Chromium security severity: Medium)

πŸ“… Published: Sept. 17, 2024, 9:07 p.m. πŸ”„ Last Modified: July 15, 2025, 6:23 p.m.

4.3

CVSS3.1

CVE-2024-8906 -

Incorrect security UI in Downloads in Google Chrome prior to 129.0.6668.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

πŸ“… Published: Sept. 17, 2024, 9:07 p.m. πŸ”„ Last Modified: March 25, 2025, 5:16 p.m.

8.8

CVSS3.1

CVE-2024-8905 -

Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium security severity: Medium)

πŸ“… Published: Sept. 17, 2024, 9:07 p.m. πŸ”„ Last Modified: Jan. 2, 2025, 5:33 p.m.

8.8

CVSS3.1

CVE-2024-8904 -

Type Confusion in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: Sept. 17, 2024, 9:07 p.m. πŸ”„ Last Modified: Jan. 2, 2025, 5:34 p.m.

6.5

CVSS3.1

CVE-2024-45815 - Prototype pollution in @backstage/plugin-catalog-backend

Backstage is an open framework for building developer portals. A malicious actor with authenticated access to a Backstage instance with the catalog backend plugin installed is able to interrupt the service using a specially crafted query to the catalog API. This has been fixed in the `1.26.0` relea…

πŸ“… Published: Sept. 17, 2024, 8:14 p.m. πŸ”„ Last Modified: Jan. 3, 2025, 2:53 p.m.

6.5

CVSS3.1

CVE-2024-45816 - Storage bucket Directory Traversal in @backstage/plugin-techdocs-backend

Backstage is an open framework for building developer portals. When using the AWS S3 or GCS storage provider for TechDocs it is possible to access content in the entire storage bucket. This can leak contents of the bucket that are not intended to be accessible, as well as bypass permission checks i…

πŸ“… Published: Sept. 17, 2024, 8:13 p.m. πŸ”„ Last Modified: Jan. 3, 2025, 2:52 p.m.

6.5

CVSS3.1

CVE-2024-46976 - Circumvention of cross site scripting Protection in @backstage/plugin-techdocs-backend

Backstage is an open framework for building developer portals. An attacker with control of the contents of the TechDocs storage buckets is able to inject executable scripts in the TechDocs content that will be executed in the victim's browser when browsing documentation or navigating to an attacker…

πŸ“… Published: Sept. 17, 2024, 8:12 p.m. πŸ”„ Last Modified: Jan. 3, 2025, 2:52 p.m.
Total resulsts: 349182
Page 8538 of 34,919
Β« previous page Β» next page
Filters