3.5

CVSS3.1

CVE-2024-39307 - Cross-Site Scripting (XSS) vulnerability via crafted ebooks in Kavita

Kavita is a cross platform reading server. Opening an ebook with malicious scripts inside leads to code execution inside the browsing context. Kavita doesn't sanitize or sandbox the contents of epubs, allowing scripts inside ebooks to execute. This vulnerability was patched in version 0.8.1.

๐Ÿ“… Published: June 28, 2024, 8:44 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.6

CVSS3.1

CVE-2024-38518 - bbb-web API additional parameters considered

BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker with a valid join link to a meeting can trick BigBlueButton into generating a signed join link with additional parameters. One of those parameters may be "role=moderator", allowing an aโ€ฆ

๐Ÿ“… Published: June 28, 2024, 8:25 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

2

CVSS4.0

CVE-2024-3995 - Command Injection in Helix ALM

In Helix ALM versions prior to 2024.2.0, a local command injection was identified. Reported by Bryan Riggins.

๐Ÿ“… Published: June 28, 2024, 7:46 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-38528 - Unlimited number of NTS-KE connections can crash ntpd-rs server

nptd-rs is a tool for synchronizing your computer's clock, implementing the NTP and NTS protocols. There is a missing limit for accepted NTS-KE connections. This allows an unauthenticated remote attacker to crash ntpd-rs when an NTS-KE server is configured. Non NTS-KE server configurations, such asโ€ฆ

๐Ÿ“… Published: June 28, 2024, 7:28 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.0

CVE-2024-5827 - Arbitrary File Write by Prompt Injection via DuckDB SQL in vanna-ai/vanna

Vanna v0.3.4 is vulnerable to SQL injection in its DuckDB integration exposed to its Flask Web APIs. Attackers can inject malicious SQL training data and generate corresponding queries to write arbitrary files on the victim's file system, such as backdoor.php with contents `<?php system($_GET[0]); โ€ฆ

๐Ÿ“… Published: June 28, 2024, 7:27 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.0

CVE-2024-5712 - CSRF Vulnerability in stitionai/devika

A Cross-Site Request Forgery (CSRF) vulnerability was identified in the stitionai/devika application, affecting the latest version. This vulnerability allows attackers to perform unauthorized actions in the context of a victim's browser, such as deleting projects or changing application settings, wโ€ฆ

๐Ÿ“… Published: June 28, 2024, 7:19 p.m. ๐Ÿ”„ Last Modified: July 15, 2025, 1:25 p.m.

4

CVSS3.1

CVE-2022-38383 - IBM Cloud Pak for Security information disclosure

IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Software Suite 1.10.12.0 through 1.10.21.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 233673.

๐Ÿ“… Published: June 28, 2024, 7:03 p.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 7:16 a.m.

7.8

CVSS3.1

CVE-2022-27540 -

A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC products, which might allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability.

๐Ÿ“… Published: June 28, 2024, 7 p.m. ๐Ÿ”„ Last Modified: Jan. 30, 2026, 8:53 p.m.

5.4

CVSS3.1

CVE-2024-25041 - IBM Cognos Analytics cross-site scripting

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is potentially vulnerable to cross site scripting (XSS). A remote attacker could execute malicious commands due to improper validation of column headings in Cognos Assistant. IBM X-Force ID: 282780.

๐Ÿ“… Published: June 28, 2024, 6:55 p.m. ๐Ÿ”„ Last Modified: Nov. 3, 2025, 10:16 p.m.

5.9

CVSS3.1

CVE-2024-25053 - IBM Cognos Analytics improper certificate validation

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is vulnerable to improper certificate validation when using the IBM Planning Analytics Data Source Connection. This could allow an attacker to spoof a trusted entity by interfering in the communication path betwโ€ฆ

๐Ÿ“… Published: June 28, 2024, 6:53 p.m. ๐Ÿ”„ Last Modified: Nov. 3, 2025, 10:16 p.m.
Total resulsts: 349182
Page 9304 of 34,919
ยซ previous page ยป next page
Filters