5.5

CVSS3.1

CVE-2024-39322 - aimeos/ai-admin-jsonadm improper access control vulnerability allows editors to remove required rec…

aimeos/ai-admin-jsonadm is the Aimeos e-commerce JSON API for administrative tasks. In versions prior to 2020.10.13, 2021.10.6, 2022.10.3, 2023.10.4, and 2024.4.2, improper access control allows editors to remove admin group and locale configuration in the Aimeos backend. Versions 2020.10.13, 2021.…

πŸ“… Published: July 2, 2024, 8:19 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:27 a.m.

3.8

CVSS3.1

CVE-2024-39324 - aimeos/ai-admin-graphql improper access control vulnerability allows editors to manage own services

aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access control allows a editors to manage own services via GraphQL API which isn't allowed in the JQAdm front end. Versions 2022.10.10…

πŸ“… Published: July 2, 2024, 8:09 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:27 a.m.

5.7

CVSS3.1

CVE-2024-39315 - Pomerium exposed OAuth2 access and ID tokens in user info endpoint response

Pomerium is an identity and context-aware access proxy. Prior to version 0.26.1, the Pomerium user info page (at `/.pomerium`) unintentionally included serialized OAuth2 access and ID tokens from the logged-in user's session. These tokens are not intended to be exposed to end users. This issue may …

πŸ“… Published: July 2, 2024, 8:02 p.m. πŸ”„ Last Modified: April 11, 2025, 2:47 p.m.

5.3

CVSS4.0

CVE-2024-6452 - linlinjava litemall AdminGoodscontroller.java sql injection

A vulnerability classified as critical was found in linlinjava litemall up to 1.8.0. Affected by this vulnerability is an unknown functionality of the file AdminGoodscontroller.java. The manipulation of the argument goodsId/goodsSn/name leads to sql injection. The attack can be launched remotely. T…

πŸ“… Published: July 2, 2024, 8 p.m. πŸ”„ Last Modified: Sept. 11, 2025, 3:08 p.m.

9.8

CVSS3.1

CVE-2023-24531 - Output of "go env" does not sanitize values in cmd/go

Command go env is documented as outputting a shell script containing the Go environment. However, go env doesn't sanitize values, so executing its output as a shell script can cause various bad bahaviors, including executing arbitrary commands or inserting new environment variables. This issue is r…

πŸ“… Published: July 2, 2024, 7:51 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2022-30636 - Limited directory traversal vulnerability on Windows in golang.org/x/crypto

httpTokenCacheKey uses path.Base to extract the expected HTTP-01 token value to lookup in the DirCache implementation. On Windows, path.Base acts differently to filepath.Base, since Windows uses a different path separator (\ vs. /), allowing a user to provide a relative path, i.e. .well-known/acme-…

πŸ“… Published: July 2, 2024, 7:51 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0

CVSS3.1

CVE-2024-38537 - Inclusion of Untrusted polyfill.io Code Vulnerability in fides.js

Fides is an open-source privacy engineering platform. `fides.js`, a client-side script used to interact with the consent management features of Fides, used the `polyfill.io` domain in a very limited edge case, when it detected a legacy browser such as IE11 that did not support the fetch standard. T…

πŸ“… Published: July 2, 2024, 7:50 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 8:27 p.m.

6.4

CVSS3.1

CVE-2024-6382 - Adversarial unsanitized input may cause MongoDB Rust Driver to issue unintended commands.

Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected application behavior including data modification. This issue affects MongoDB Rust Driver 2.0 versions prior to 2.8.2

πŸ“… Published: July 2, 2024, 5:17 p.m. πŸ”„ Last Modified: Oct. 2, 2025, 1:48 p.m.

4

CVSS3.1

CVE-2024-6381 - MongoDB C Driver bson_strfreev may be susceptible to integer overflow

The bson_strfreev function in the MongoDB C driver library may be susceptible to an integer overflow where the function will try to free memory at a negative offset. This may result in memory corruption. This issue affected libbson versions prior to 1.26.2

πŸ“… Published: July 2, 2024, 5:14 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.

7.1

CVSS3.1

CVE-2024-39323 - aimeos/ai-admin-graphql improper access control vulnerability allows an editor to modify admin acco…

aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability allows an editor to modify and take over an admin account in the back end. Versions 2022.10.10, 2023…

πŸ“… Published: July 2, 2024, 4:03 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347769
Page 9133 of 34,777
Β« previous page Β» next page
Filters