7.5

CVSS3.1

CVE-2024-38461 -

irodsServerMonPerf in iRODS before 4.3.2 attempts to proceed with use of a path even if it is not a directory.

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:25 a.m.

9.1

CVSS3.1

CVE-2024-38448 -

htags in GNU Global through 6.6.12 allows code execution in situations where dbpath (aka -d) is untrusted, because shell metacharacters may be used.

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-38458 -

Xenforo before 2.2.16 allows code injection.

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:25 a.m.

9.8

CVSS3.1

CVE-2024-38466 -

Shenzhen Guoxin Synthesis image system before 8.3.0 has a 123456Qw default password.

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: March 19, 2025, 8:15 p.m.

6.5

CVSS3.1

CVE-2023-27636 -

Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor.

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 21, 2024, 7:53 a.m.

7.5

CVSS3.1

CVE-2024-38440 -

Netatalk before 3.2.1 has an off-by-one error, and resultant heap-based buffer overflow and segmentation violation, because of incorrectly using FPLoginExt in BN_bin2bn in etc/uams/uams_dhx_pam.c. The original issue 1097 report stated: 'The latest version of Netatalk (v3.2.0) contains a security vuโ€ฆ

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 3, 2025, 10:17 p.m.

9.8

CVSS3.1

CVE-2024-38395 -

In iTerm2 before 3.5.2, the "Terminal may report window title" setting is not honored, and thus remote code execution might occur but "is not trivially exploitable."

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: June 18, 2025, 4:40 p.m.

7.5

CVSS3.1

CVE-2024-38467 -

Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized user information retrieval via the queryUser API.

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: June 20, 2025, 7:01 p.m.

4.9

CVSS3.1

CVE-2024-38460 -

In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartext as part of the URL parameters in the logs (such as SonarQube Access Logs, Proxy Logs, etc).

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: March 13, 2025, 3:15 p.m.

9.1

CVSS3.1

CVE-2024-34451 -

Ghost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection mechanism by using many X-Forwarded-For headers with different values. NOTE: the vendor's position is that Ghost should be installed with a reverse proxy that allows only trusted X-Forwarded-For headers.

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: June 20, 2025, 6:06 p.m.
Total resulsts: 347769
Page 9285 of 34,777
ยซ previous page ยป next page
Filters