4.7
CVE-2024-2965 - Denial-of-Service in LangChain SitemapLoader in langchain-ai/langchain
A Denial-of-Service (DoS) vulnerability exists in the `SitemapLoader` class of the `langchain-ai/langchain` repository, affecting all versions. The `parse_sitemap` method, responsible for parsing sitemaps and extracting URLs, lacks a mechanism to prevent infinite recursion when a sitemap URL refersโฆ
7.5
CVE-2023-49441 - dnsmasq: vulnerable to Integer Overflow via forward_query
dnsmasq 2.9 is vulnerable to Integer Overflow via forward_query.
8.5
CVE-2024-0912 - CCURE passwords exposed to administrators
Under certain circumstances the Microsoftยฎ Internet Information Server (IIS) used to host the CโขCURE 9000 Web Server will log Microsoft Windows credential details within logs. There is no impact to non-web service interfaces CโขCURE 9000 or prior versions
6.9
CVE-2024-5653 - Chanjet Smooth T+system keyEdit.aspx sql injection
A vulnerability, which was classified as critical, has been found in Chanjet Smooth T+system 3.5. This issue affects some unknown processing of the file /tplus/UFAQD/keyEdit.aspx. The manipulation of the argument KeyID leads to sql injection. The attack may be initiated remotely. The exploit has beโฆ
8.8
CVE-2024-36667 -
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/idcProType_deal.php?mudi=add&nohrefStr=close
5.4
CVE-2024-36668 -
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/type_deal.php?mudi=del
8.8
CVE-2024-36670 -
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/vpsClass_deal.php?mudi=del
5.4
CVE-2024-36669 -
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/type_deal.php?mudi=add.
6.7
CVE-2024-27371 -
An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_followup_get_nl_params(), there is no input validation check on hal_req->service_specific_info_len coming from userspace, which can lead to a heap overwritโฆ
6.7
CVE-2024-27373 -
An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_config_get_nl_params(), there is no input validation check on disc_attr->mesh_id_len coming from userspace, which can lead to a heap overwrite.