7.5

CVSS3.1

CVE-2024-44073 -

The Miniscript (aka rust-miniscript) library before 12.2.0 for Rust allows stack consumption because it does not properly track tree depth.

πŸ“… Published: Aug. 19, 2024, midnight πŸ”„ Last Modified: Sept. 13, 2024, 1:28 p.m.

9.8

CVSS3.1

CVE-2024-44076 -

In Microcks before 1.10.0, the POST /api/import and POST /api/export endpoints allow non-administrator access.

πŸ“… Published: Aug. 19, 2024, midnight πŸ”„ Last Modified: Aug. 21, 2024, 12:33 p.m.

5.3

CVSS3.1

CVE-2024-43380 - fugit parse and parse_nat stall on lengthy input

fugit contains time tools for flor and the floraison group. The fugit "natural" parser, that turns "every wednesday at 5pm" into "0 17 * * 3", accepted any length of input and went on attempting to parse it, not returning promptly, as expected. The parse call could hold the thread with no end in si…

πŸ“… Published: Aug. 19, 2024, midnight πŸ”„ Last Modified: Sept. 3, 2024, 3:03 p.m.

8

CVSS3.1

CVE-2024-42633 -

A Command Injection vulnerability exists in the do_upgrade_post function of the httpd binary in Linksys E1500 v1.0.06.001. As a result, an authenticated attacker can execute OS commands with root privileges.

πŸ“… Published: Aug. 19, 2024, midnight πŸ”„ Last Modified: Aug. 20, 2024, 4:18 p.m.

8.8

CVSS3.1

CVE-2024-42658 -

An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the cookie's parameter

πŸ“… Published: Aug. 19, 2024, midnight πŸ”„ Last Modified: Aug. 20, 2024, 4:12 p.m.

7.5

CVSS3.1

CVE-2024-7592 - Quadratic complexity parsing cookies with backslashes

There is a LOW severity vulnerability affecting CPython, specifically the 'http.cookies' standard library module. When parsing cookies that contained backslashes for quoted characters in the cookie value, the parser would use an algorithm with quadratic complexity, resulting in excess CPU resourc…

πŸ“… Published: Aug. 19, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:17 p.m.

9.8

CVSS3.1

CVE-2024-42815 -

In the TP-Link RE365 V1_180213, there is a buffer overflow vulnerability due to the lack of length verification for the USER_AGENT field in /usr/bin/httpd. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.

πŸ“… Published: Aug. 19, 2024, midnight πŸ”„ Last Modified: July 9, 2025, 2:47 p.m.

8

CVSS3.1

CVE-2024-6508 - Openshift-console: oauth2 insufficient state parameter entropy

An insufficient entropy vulnerability was found in the Openshift Console. In the authorization code type and implicit grant type, the OAuth2 protocol is vulnerable to a Cross-Site Request Forgery (CSRF) attack if the state parameter is used inefficiently. This flaw allows logging into the victim’s …

πŸ“… Published: Aug. 19, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-42657 -

An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the lack of encryption during login process

πŸ“… Published: Aug. 19, 2024, midnight πŸ”„ Last Modified: Aug. 20, 2024, 4:13 p.m.

5.3

CVSS3.1

CVE-2024-35538 -

Typecho v1.3.0 was discovered to contain a Client IP Spoofing vulnerability, which allows attackers to falsify their IP addresses by specifying an arbitrary IP as value of X-Forwarded-For or Client-Ip headers while performing HTTP requests.

πŸ“… Published: Aug. 19, 2024, midnight πŸ”„ Last Modified: April 28, 2025, 2 p.m.
Total resulsts: 349182
Page 8806 of 34,919
Β« previous page Β» next page
Filters