9.1

CVSS3.1

CVE-2024-38448 -

htags in GNU Global through 6.6.12 allows code execution in situations where dbpath (aka -d) is untrusted, because shell metacharacters may be used.

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-38458 -

Xenforo before 2.2.16 allows code injection.

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:25 a.m.

9.8

CVSS3.1

CVE-2024-38466 -

Shenzhen Guoxin Synthesis image system before 8.3.0 has a 123456Qw default password.

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: March 19, 2025, 8:15 p.m.

6.5

CVSS3.1

CVE-2023-27636 -

Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor.

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 21, 2024, 7:53 a.m.

7.5

CVSS3.1

CVE-2024-38440 -

Netatalk before 3.2.1 has an off-by-one error, and resultant heap-based buffer overflow and segmentation violation, because of incorrectly using FPLoginExt in BN_bin2bn in etc/uams/uams_dhx_pam.c. The original issue 1097 report stated: 'The latest version of Netatalk (v3.2.0) contains a security vuโ€ฆ

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 3, 2025, 10:17 p.m.

9.8

CVSS3.1

CVE-2024-38395 -

In iTerm2 before 3.5.2, the "Terminal may report window title" setting is not honored, and thus remote code execution might occur but "is not trivially exploitable."

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: June 18, 2025, 4:40 p.m.

7.5

CVSS3.1

CVE-2024-38467 -

Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized user information retrieval via the queryUser API.

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: June 20, 2025, 7:01 p.m.

4.9

CVSS3.1

CVE-2024-38460 -

In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartext as part of the URL parameters in the logs (such as SonarQube Access Logs, Proxy Logs, etc).

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: March 13, 2025, 3:15 p.m.

9.1

CVSS3.1

CVE-2024-34451 -

Ghost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection mechanism by using many X-Forwarded-For headers with different values. NOTE: the vendor's position is that Ghost should be installed with a reverse proxy that allows only trusted X-Forwarded-For headers.

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: June 20, 2025, 6:06 p.m.

7.5

CVSS3.1

CVE-2024-37890 - Denial of service when handling a request with many HTTP headers in ws

ws is an open source WebSocket client and server for Node.js. A request with a number of headers exceeding theserver.maxHeadersCount threshold could be used to crash a ws server. The vulnerability was fixed in [email protected] (e55e510) and backported to [email protected] (22c2876), [email protected] (eeb76d3), and [email protected]โ€ฆ

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347748
Page 9283 of 34,775
ยซ previous page ยป next page
Filters