7.6

CVSS3.1

CVE-2024-36581 -

A Prototype Pollution issue in abw badger-database 1.2.1 allows an attacker to execute arbitrary code via dist/badger-database.esm.

πŸ“… Published: June 17, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-36580 -

A Prototype Pollution issue in cdr0 sg 1.0.10 allows an attacker to execute arbitrary code.

πŸ“… Published: June 17, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.2

CVSS3.1

CVE-2024-37305 - Buffer overflow in deserialization in oqs-provider

oqs-provider is a provider for the OpenSSL 3 cryptography library that adds support for post-quantum cryptography in TLS, X.509, and S/MIME using post-quantum algorithms from liboqs. Flaws have been identified in the way oqs-provider handles lengths decoded with DECODE_UINT32 at the start of serial…

πŸ“… Published: June 17, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.3

CVSS3.1

CVE-2024-36577 -

apphp js-object-resolver < 3.1.1 is vulnerable to Prototype Pollution via Module.setNestedProperty.

πŸ“… Published: June 17, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.4

CVSS3.1

CVE-2024-37891 - Proxy-Authorization request header isn't stripped during cross-origin redirects in urllib3

urllib3 is a user-friendly HTTP client library for Python. When using urllib3's proxy support with `ProxyManager`, the `Proxy-Authorization` header is only sent to the configured proxy, as expected. However, when sending HTTP requests *without* using urllib3's proxy support, it's possible to accid…

πŸ“… Published: June 17, 2024, midnight πŸ”„ Last Modified: Jan. 6, 2026, 4:52 p.m.

6.3

CVSS3.1

CVE-2024-36574 -

A Prototype Pollution issue in flatten-json 1.0.1 allows an attacker to execute arbitrary code via module.exports.unflattenJSON (flatten-json/index.js:42)

πŸ“… Published: June 17, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.4

CVSS3.1

CVE-2024-37848 -

SQL Injection vulnerability in Online-Bookstore-Project-In-PHP v1.0 allows a local attacker to execute arbitrary code via the admin_delete.php component.

πŸ“… Published: June 17, 2024, midnight πŸ”„ Last Modified: Nov. 5, 2025, 10:07 p.m.

5.2

CVSS3.1

CVE-2024-37664 -

Redmi router RB03 v1.0.57 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can disconnect or hijack the traffic between the victim and any remote server by sending out forged TCP RST messages to evict NAT mappings in the router.

πŸ“… Published: June 17, 2024, midnight πŸ”„ Last Modified: July 9, 2025, 3:05 p.m.

7.2

CVSS3.1

CVE-2024-37621 -

StrongShop v1.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the component /shippingOptionConfig/index.blade.php.

πŸ“… Published: June 17, 2024, midnight πŸ”„ Last Modified: June 20, 2025, 6:06 p.m.

9.8

CVSS3.1

CVE-2023-37057 -

An issue in JLINK Unionman Technology Co. Ltd Jlink AX1800 v.1.0 allows a remote attacker to execute arbitrary code via the router's authentication mechanism.

πŸ“… Published: June 17, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347742
Page 9279 of 34,775
Β« previous page Β» next page
Filters