6.1

CVSS3.1

CVE-2024-41599 -

Cross Site Scripting vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the file upload method

πŸ“… Published: July 19, 2024, midnight πŸ”„ Last Modified: March 19, 2025, 6:15 p.m.

7.5

CVSS3.1

CVE-2024-41172 - Apache CXF: Unrestricted memory consumption in CXF HTTP clients

In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF HTTP client conduit may prevent HTTPClient instances from being garbage collected and it is possible that memory consumption will continue to increase, eventually causing the application to run out …

πŸ“… Published: July 19, 2024, midnight πŸ”„ Last Modified: Nov. 21, 2024, 9:32 a.m.

7.5

CVSS3.1

CVE-2024-32007 - Apache CXF Denial of Service vulnerability in JOSE

An improper input validation of theΒ p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9Β allows an attacker to perform a denial of service attack by specifying a large value for this parameter in a token.Β 

πŸ“… Published: July 19, 2024, midnight πŸ”„ Last Modified: Nov. 21, 2024, 9:14 a.m.

7.5

CVSS3.1

CVE-2024-41492 -

A stack overflow in Tenda AX1806 v1.0.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

πŸ“… Published: July 19, 2024, midnight πŸ”„ Last Modified: April 7, 2025, 5:27 p.m.

8

CVSS3.1

CVE-2024-39963 -

AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX9 V22.03.01.46 and AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX12 V1.0 V22.03.01.46 were discovered to contain an authenticated remote command execution (RCE) vulnerability via the macFilterType parameter at /goform/setMacFilterCfg.

πŸ“… Published: July 19, 2024, midnight πŸ”„ Last Modified: June 4, 2025, 5:02 p.m.

5.4

CVSS3.1

CVE-2024-39123 -

In janeczku Calibre-Web 0.6.0 to 0.6.21, the edit_book_comments function is vulnerable to Cross Site Scripting (XSS) due to improper sanitization performed by the clean_string function. The vulnerability arises from the way the clean_string function handles HTML sanitization.

πŸ“… Published: July 19, 2024, midnight πŸ”„ Last Modified: July 9, 2025, 3:28 p.m.

9.6

CVSS3.1

CVE-2024-41603 -

Spina CMS v2.18.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the URI /admin/layout.

πŸ“… Published: July 19, 2024, midnight πŸ”„ Last Modified: May 29, 2025, 4:08 p.m.

7.5

CVSS3.1

CVE-2024-7006 - Libtiff: null pointer dereference in tif_dirinfo.c

A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger memory allocation failures through certain means, such as restricting the heap space size or injecting faults, causing a segmentation fault. This can cause an application crash, eve…

πŸ“… Published: July 19, 2024, midnight πŸ”„ Last Modified: Jan. 23, 2026, 5 p.m.

4.2

CVSS3.1

CVE-2024-41597 -

Cross Site Request Forgery vulnerability in ProcessWire v.3.0.229 allows a remote attacker to execute arbitrary code via a crafted HTML file to the comments functionality.

πŸ“… Published: July 19, 2024, midnight πŸ”„ Last Modified: July 9, 2025, 3:23 p.m.

7.5

CVSS3.1

CVE-2024-41601 -

Insecure Permissions vulnerability in lin-CMS v.0.2.0 and before allows a remote attacker to obtain sensitive information via the login method in the UserController.java component.

πŸ“… Published: July 19, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 9104 of 34,919
Β« previous page Β» next page
Filters