6.8

CVSS3.1

CVE-2024-40644 - gitoxide's gix-path can use a fake program files location

gitoxide An idiomatic, lean, fast & safe pure Rust implementation of Git. `gix-path` can be tricked into running another `git.exe` placed in an untrusted location by a limited user account on Windows systems. Windows permits limited user accounts without administrative privileges to create new dire…

πŸ“… Published: July 18, 2024, 4:56 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-40647 - Unintentional exposure of environment variables to subprocesses in sentry-sdk

sentry-sdk is the official Python SDK for Sentry.io. A bug in Sentry's Python SDK < 2.8.0 allows the environment variables to be passed to subprocesses despite the `env={}` setting. In Python's `subprocess` calls, all environment variables are passed to subprocesses by default. However, if you spec…

πŸ“… Published: July 18, 2024, 4:51 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.6

CVSS3.1

CVE-2024-5619 - IDOR in PruvaSoft Informatics' Apinizer Management Console

Authorization Bypass Through User-Controlled Key vulnerability in PruvaSoft Informatics Apinizer Management Console allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Apinizer Management Console: before 2024.05.1.

πŸ“… Published: July 18, 2024, 4:49 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-40648 - `UserIdentity::is_verified` not checking verification status of own user identity while performing …

matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. The `UserIdentity::is_verified()` method in the matrix-sdk-crypto crate before version 0.7.2 doesn't take into account the verification status of the user's own identity while performing the check and may as a result re…

πŸ“… Published: July 18, 2024, 4:45 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.7

CVSS4.0

CVE-2023-40704 - Philips Vue PACS Use of Default Credentials

The product does not require unique and complex passwords to be created during installation. Using Philips's default password could jeopardize the PACS system if the password was hacked or leaked. An attacker could gain access to the database impacting system availability and data integrity.

πŸ“… Published: July 18, 2024, 4:33 p.m. πŸ”„ Last Modified: Aug. 27, 2025, 8:32 p.m.

0.0

CVE-2023-40539 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: July 18, 2024, 4:29 p.m. πŸ”„ Last Modified: April 9, 2025, 9:16 p.m.

9.9

CVSS3.1

CVE-2024-5618 - Broken Access Control in PruvaSoft Informatics' Apinizer Management Console

Incorrect Permission Assignment for Critical Resource vulnerability in PruvaSoft Informatics Apinizer Management Console allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Apinizer Management Console: before 2024.05.1.

πŸ“… Published: July 18, 2024, 4:28 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2023-40223 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: July 18, 2024, 4:23 p.m. πŸ”„ Last Modified: April 9, 2025, 9:16 p.m.

0.0

CVE-2023-40159 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: July 18, 2024, 4:19 p.m. πŸ”„ Last Modified: April 9, 2025, 9:15 p.m.

7.1

CVSS3.1

CVE-2023-50304 - IBM Engineering Requirements Management DOORS XML external entity injection

IBM Engineering Requirements Management DOORS Web Access 9.7.2.8 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 273335.

πŸ“… Published: July 18, 2024, 4:01 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 8:36 a.m.
Total resulsts: 349182
Page 9107 of 34,919
Β« previous page Β» next page
Filters