7.5

CVSS3.1

CVE-2024-38467 -

Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized user information retrieval via the queryUser API.

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: June 20, 2025, 7:01 p.m.

4.9

CVSS3.1

CVE-2024-38460 -

In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartext as part of the URL parameters in the logs (such as SonarQube Access Logs, Proxy Logs, etc).

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: March 13, 2025, 3:15 p.m.

9.1

CVSS3.1

CVE-2024-34451 -

Ghost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection mechanism by using many X-Forwarded-For headers with different values. NOTE: the vendor's position is that Ghost should be installed with a reverse proxy that allows only trusted X-Forwarded-For headers.

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: June 20, 2025, 6:06 p.m.

7.5

CVSS3.1

CVE-2024-37890 - Denial of service when handling a request with many HTTP headers in ws

ws is an open source WebSocket client and server for Node.js. A request with a number of headers exceeding theserver.maxHeadersCount threshold could be used to crash a ws server. The vulnerability was fixed in [email protected] (e55e510) and backported to [email protected] (22c2876), [email protected] (eeb76d3), and [email protected]โ€ฆ

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-38396 -

An issue was discovered in iTerm2 3.5.x before 3.5.2. Unfiltered use of an escape sequence to report a window title, in combination with the built-in tmux integration feature (enabled by default), allows an attacker to inject arbitrary code into the terminal, a different vulnerability than CVE-2024โ€ฆ

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: June 20, 2025, 6:05 p.m.

9.8

CVSS3.1

CVE-2024-38441 -

Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[len] to '\0' in FPMapName in afp_mapname in etc/afpd/directory.c. 2.4.1 and 3.1.19 are also fixed versions.

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 3, 2025, 10:17 p.m.

6.1

CVSS3.1

CVE-2024-38454 -

ExpressionEngine before 7.4.11 allows XSS.

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: March 17, 2025, 2:15 p.m.

8.8

CVSS3.1

CVE-2024-38427 -

In International Color Consortium DemoIccMAX before 85ce74e, a logic flaw in CIccTagXmlProfileSequenceId::ParseXml in IccXML/IccLibXML/IccTagXml.cpp results in unconditionally returning false.

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-38462 -

iRODS before 4.3.2 provides an msiSendMail function with a problematic dependency on the mail binary, such as in the mailMS.cpp#L94-L106 reference.

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:25 a.m.

7.8

CVSS3.1

CVE-2024-38459 -

langchain_experimental (aka LangChain Experimental) before 0.0.61 for LangChain provides Python REPL access without an opt-in step. NOTE; this issue exists because of an incomplete fix for CVE-2024-27444.

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: July 16, 2025, 4:23 p.m.
Total resulsts: 347752
Page 9284 of 34,776
ยซ previous page ยป next page
Filters