7.8

CVSS3.1

CVE-2024-37391 -

ProtonVPN before 3.2.10 on Windows mishandles the drive installer path, which should use this: '"' + ExpandConstant('{autopf}\Proton\Drive') + '"' in Setup/setup.iss.

πŸ“… Published: July 22, 2024, midnight πŸ”„ Last Modified: March 13, 2025, 3:15 p.m.

6.8

CVSS3.1

CVE-2024-41315 -

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wps function.

πŸ“… Published: July 22, 2024, midnight πŸ”„ Last Modified: April 3, 2025, 3:48 p.m.

9.8

CVSS3.1

CVE-2024-39250 -

EfroTech Timetrax v8.3 was discovered to contain an unauthenticated SQL injection vulnerability via the q parameter in the search web interface.

πŸ“… Published: July 22, 2024, midnight πŸ”„ Last Modified: July 8, 2025, 2:22 p.m.

5.4

CVSS3.1

CVE-2024-41703 -

LibreChat through 0.7.4-rc1 has incorrect access control for message updates.

πŸ“… Published: July 22, 2024, midnight πŸ”„ Last Modified: Nov. 21, 2024, 9:33 a.m.

5.3

CVSS3.1

CVE-2024-41880 -

In veilid-core in Veilid before 0.3.4, the protocol's ping function can be misused in a way that decreases the effectiveness of safety and private routes.

πŸ“… Published: July 22, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-40634 - Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. This report details a security vulnerability in Argo CD, where an unauthenticated attacker can send a specially crafted large JSON payload to the /api/webhook endpoint, causing excessive memory allocation that leads to servic…

πŸ“… Published: July 22, 2024, midnight πŸ”„ Last Modified: Jan. 9, 2025, 4:55 p.m.

4.3

CVSS3.1

CVE-2024-40075 -

Laravel v11.x was discovered to contain an XML External Entity (XXE) vulnerability.

πŸ“… Published: July 22, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-41318 -

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function.

πŸ“… Published: July 22, 2024, midnight πŸ”„ Last Modified: April 3, 2025, 3:48 p.m.

9.8

CVSS3.1

CVE-2024-41316 -

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function.

πŸ“… Published: July 22, 2024, midnight πŸ”„ Last Modified: April 3, 2025, 3:48 p.m.

8

CVSS3.1

CVE-2024-41317 -

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pbc_wps function.

πŸ“… Published: July 22, 2024, midnight πŸ”„ Last Modified: April 3, 2025, 3:48 p.m.
Total resulsts: 349182
Page 9082 of 34,919
Β« previous page Β» next page
Filters