3.7

CVSS3.1

CVE-2024-40632 - Linkerd potential access to the shutdown endpoint

Linkerd is an open source, ultralight, security-first service mesh for Kubernetes. In affected versions when the application being run by linkerd is susceptible to SSRF, an attacker could potentially trigger a denial-of-service (DoS) attack by making requests to localhost:4191/shutdown. Linkerd cou…

πŸ“… Published: July 15, 2024, 9:22 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:31 a.m.

5.4

CVSS3.1

CVE-2024-4224 - TP-Link TL-SG1016DE XSS

An authenticated stored cross-site scripting (XSS) exists in the TP-Link TL-SG1016DE affecting version TL-SG1016DE(UN) V7.6_1.0.0 Build 20230616, which could allow an adversary to run JavaScript in an administrator's browser. This issue was fixed inΒ TL-SG1016DE(UN) V7_1.0.1 Build 20240628.

πŸ“… Published: July 15, 2024, 8:34 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:42 a.m.

3.1

CVSS3.1

CVE-2024-39919 - Capture screenshot of localhost web services (unauthenticated pages) in @jmondi/url-to-png

@jmondi/url-to-png is an open source URL to PNG utility featuring parallel rendering using Playwright for screenshots and with storage caching via Local, S3, or CouchDB. The package includes an `ALLOW_LIST` where the host can specify which services the user is permitted to capture screenshots of. B…

πŸ“… Published: July 15, 2024, 7:53 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:28 a.m.

4.3

CVSS3.1

CVE-2024-39918 - Path Traveral in @jmondi/url-to-png

@jmondi/url-to-png is an open source URL to PNG utility featuring parallel rendering using Playwright for screenshots and with storage caching via Local, S3, or CouchDB. Input of the `ImageId` in the code is not sanitized and may lead to path traversal. This allows an attacker to store an image in …

πŸ“… Published: July 15, 2024, 7:53 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:28 a.m.

4.9

CVSS3.1

CVE-2024-38360 - Denial of service via Watched Words in Discourse

Discourse is an open source platform for community discussion. In affected versions by creating replacement words with an almost unlimited number of characters, a moderator can reduce the availability of a Discourse instance. This issue has been addressed in stable version 3.2.3 and in current beta…

πŸ“… Published: July 15, 2024, 7:43 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 7:13 p.m.

5.3

CVSS3.1

CVE-2024-39912 - Enumeration of valid usernames in web-auth/webauthn-lib

web-auth/webauthn-lib is an open source set of PHP libraries and a Symfony bundle to allow developers to integrate that authentication mechanism into their web applications. The ProfileBasedRequestOptionsBuilder method returns allowedCredentials without any credentials if no username was found. Whe…

πŸ“… Published: July 15, 2024, 7:38 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:28 a.m.

10

CVSS3.1

CVE-2024-39915 - Authenticated remote code execution in Thruk

Thruk is a multibackend monitoring webinterface for Naemon, Nagios, Icinga and Shinken using the Livestatus API. This authenticated RCE in Thruk allows authorized users with network access to inject arbitrary commands via the URL parameter during PDF report generation. The Thruk web application doe…

πŸ“… Published: July 15, 2024, 7:33 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:28 a.m.

9.8

CVSS3.1

CVE-2024-40624 - Deserialization of untrusted data in torrentpier/torrentpier

TorrentPier is an open source BitTorrent Public/Private tracker engine, written in php. In `torrentpier/library/includes/functions.php`, `get_tracks()` uses the unsafe native PHP serialization format to deserialize user-controlled cookies. One can use phpggc and the chain Guzzle/FW1 to write PHP co…

πŸ“… Published: July 15, 2024, 7:28 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:31 a.m.

5.8

CVSS3.1

CVE-2024-40627 - OpaMiddleware does not filter HTTP OPTIONS requests

Fastapi OPA is an opensource fastapi middleware which includes auth flow. HTTP `OPTIONS` requests are always allowed by `OpaMiddleware`, even when they lack authentication, and are passed through directly to the application. `OpaMiddleware` allows all HTTP `OPTIONS` requests without evaluating it a…

πŸ“… Published: July 15, 2024, 7:21 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:31 a.m.

0.0

CVE-2024-6765 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: July 15, 2024, 7:18 p.m. πŸ”„ Last Modified: July 17, 2024, 2:15 p.m.
Total resulsts: 344032
Page 8630 of 34,404
Β« previous page Β» next page
Filters