7.5
CVE-2024-38461 -
irodsServerMonPerf in iRODS before 4.3.2 attempts to proceed with use of a path even if it is not a directory.
9.1
CVE-2024-38448 -
htags in GNU Global through 6.6.12 allows code execution in situations where dbpath (aka -d) is untrusted, because shell metacharacters may be used.
8.8
CVE-2024-38458 -
Xenforo before 2.2.16 allows code injection.
9.8
CVE-2024-38466 -
Shenzhen Guoxin Synthesis image system before 8.3.0 has a 123456Qw default password.
6.5
CVE-2023-27636 -
Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor.
7.5
CVE-2024-38440 -
Netatalk before 3.2.1 has an off-by-one error, and resultant heap-based buffer overflow and segmentation violation, because of incorrectly using FPLoginExt in BN_bin2bn in etc/uams/uams_dhx_pam.c. The original issue 1097 report stated: 'The latest version of Netatalk (v3.2.0) contains a security vuโฆ
9.8
CVE-2024-38395 -
In iTerm2 before 3.5.2, the "Terminal may report window title" setting is not honored, and thus remote code execution might occur but "is not trivially exploitable."
7.5
CVE-2024-38467 -
Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized user information retrieval via the queryUser API.
4.9
CVE-2024-38460 -
In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartext as part of the URL parameters in the logs (such as SonarQube Access Logs, Proxy Logs, etc).
9.1
CVE-2024-34451 -
Ghost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection mechanism by using many X-Forwarded-For headers with different values. NOTE: the vendor's position is that Ghost should be installed with a reverse proxy that allows only trusted X-Forwarded-For headers.