0.0

CVE-2024-41661 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-50094. Reason: This candidate is a duplicate of CVE-2023-50094. Notes: All CVE users should reference CVE-2023-50094 instead of this candidate.

πŸ“… Published: July 23, 2024, 5:22 p.m. πŸ”„ Last Modified: Aug. 29, 2024, 11:15 p.m.

5.5

CVSS3.1

CVE-2024-41665 - Ampache Stored Cross-site Scripting Vulnerability

Ampache, a web based audio/video streaming application and file manager, has a stored cross-site scripting (XSS) vulnerability in versions prior to 6.6.0. This vulnerability exists in the "Playlists - Democratic - Configure Democratic Playlist" feature. An attacker with Content Manager permissions …

πŸ“… Published: July 23, 2024, 5:14 p.m. πŸ”„ Last Modified: Feb. 3, 2025, 3:33 p.m.

5.4

CVSS3.1

CVE-2024-41664 - Blind SSRF via Canarytoken Webhook

Canarytokens help track activity and actions on a network. Prior to `sha-8ea5315`, Canarytokens.org was vulnerable to a blind SSRF in the Webhook alert feature. When a Canarytoken is created, users choose to receive alerts either via email or via a webhook. If a webhook is supplied when a Canaryto…

πŸ“… Published: July 23, 2024, 4:59 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-41178 - Apache Arrow Rust Object Store: AWS WebIdentityToken exposure in log files

Exposure of temporary credentials in logsΒ in Apache Arrow Rust Object Store (`object_store` crate), version 0.10.1 and earlier on all platforms using AWS WebIdentityTokens.Β  On certain error conditions, the logs may contain the OIDC token passed to AssumeRoleWithWebIdentity https://docs.aws.amazo…

πŸ“… Published: July 23, 2024, 4:50 p.m. πŸ”„ Last Modified: July 10, 2025, 6:24 p.m.

3.5

CVSS3.1

CVE-2024-41663 - Canarytoken "Cloned Website" Vulnerable to Stored Cross-Site Scripting

Canarytokens help track activity and actions on a network. A Cross-Site Scripting vulnerability was identified in the "Cloned Website" Canarytoken, whereby the Canarytoken's creator can attack themselves. The creator of a slow-redirect Canarytoken can insert Javascript into the destination URL of …

πŸ“… Published: July 23, 2024, 4:06 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-6714 -

An issue was discovered in provd before version 0.1.5 with a setuid binary, which allows a local attacker to escalate their privilege.

πŸ“… Published: July 23, 2024, 3:46 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 7:11 p.m.

4.8

CVSS3.1

CVE-2024-6783 - Vue client-side XSS via prototype pollution

A vulnerability has been discovered in Vue, that allows an attacker to perform XSS via prototype pollution. The attacker could change the prototype chain of some properties such as `Object.prototype.staticClass` or `Object.prototype.staticStyle` to execute arbitrary JavaScript code.

πŸ“… Published: July 23, 2024, 3:05 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-40767 - openstack-nova: Regression VMDK/qcow arbitrary file access

In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file…

πŸ“… Published: July 23, 2024, 3 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 5:15 p.m.

7.5

CVSS3.1

CVE-2024-41655 - TF2 Item Format Regular Expression Denial of Service vulnerability

TF2 Item Format helps users format TF2 items to the community standards. Versions of `tf2-item-format` since at least `4.2.6` and prior to `5.9.14` are vulnerable to a Regular Expression Denial of Service (ReDoS) attack when parsing crafted user input. This vulnerability can be exploited by an att…

πŸ“… Published: July 23, 2024, 2:49 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.4

CVSS4.0

CVE-2024-4081 - Memory Corruption Due to Improper Length Check in NI LabVIEW

A memory corruption issue due to an improper length check in NI LabVIEW may disclose information or result in arbitrary code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI. This vulnerability affects NI LabVIEW 2024 Q1 and prior versions.

πŸ“… Published: July 23, 2024, 1:32 p.m. πŸ”„ Last Modified: Sept. 30, 2025, 1:44 p.m.
Total resulsts: 349182
Page 9067 of 34,919
Β« previous page Β» next page
Filters