6.5

CVSS3.1

CVE-2024-38950 -

Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to __interceptor_memcpy function.

πŸ“… Published: June 26, 2024, midnight πŸ”„ Last Modified: June 6, 2025, 5:15 p.m.

5.3

CVSS4.0

CVE-2024-21520 - djangorestframework: Cross-site Scripting (XSS) via break_long_headers

Versions of the package djangorestframework before 3.15.2 are vulnerable to Cross-site Scripting (XSS) via the break_long_headers template filter due to improper input sanitization before splitting and joining with <br> tags.

πŸ“… Published: June 26, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-37734 -

An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter.

πŸ“… Published: June 26, 2024, midnight πŸ”„ Last Modified: May 1, 2025, 7:38 p.m.

6.5

CVSS3.1

CVE-2024-38949 -

Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to display444as420 function at sdl.cc

πŸ“… Published: June 26, 2024, midnight πŸ”„ Last Modified: June 6, 2025, 5:15 p.m.

4.3

CVSS3.1

CVE-2024-39460 - jenkins: bitbucket: Improper neutralization of OAuth credentials

Jenkins Bitbucket Branch Source Plugin 886.v44cf5e4ecec5 and earlier prints the Bitbucket OAuth access token as part of the Bitbucket URL in the build log in some cases.

πŸ“… Published: June 26, 2024, midnight πŸ”„ Last Modified: Oct. 10, 2025, 3:29 p.m.

4.3

CVSS3.1

CVE-2024-39459 - jenkins: plain-credentials: Improper storage of credentials

In rare cases Jenkins Plain Credentials Plugin 182.v468b_97b_9dcb_8 and earlier stores secret file credentials unencrypted (only Base64 encoded) on the Jenkins controller file system, where they can be viewed by users with access to the Jenkins controller file system (global credentials) or with It…

πŸ“… Published: June 26, 2024, midnight πŸ”„ Last Modified: Oct. 10, 2025, 3:26 p.m.

8.1

CVSS3.1

CVE-2024-5460 - Brocade Fabric OS versions prior to v9.0 have default community strings

A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Brocade Fabric OS versions before v9.0.0 could allow an authenticated, remote attacker to read data from an affected device via SNMP. The vulnerability is due to hard-coded, default communit…

πŸ“… Published: June 25, 2024, 11:58 p.m. πŸ”„ Last Modified: Feb. 4, 2025, 3:24 p.m.

0

CVSS3.1

CVE-2024-38526 - pdoc embeds link to malicious CDN if math mode is enabled

pdoc provides API Documentation for Python Projects. Documentation generated with `pdoc --math` linked to JavaScript files from polyfill.io. The polyfill.io CDN has been sold and now serves malicious code. This issue has been fixed in pdoc 14.5.1.

πŸ“… Published: June 25, 2024, 11:53 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.6

CVSS3.1

CVE-2024-38364 - DSpace Cross Site Scripting (XSS) via a deposited HTML/XML document

DSpace is an open source software is a turnkey repository application used by more than 2,000 organizations and institutions worldwide to provide durable access to digital resources. In DSpace 7.0 through 7.6.1, when an HTML, XML or JavaScript Bitstream is downloaded, the user's browser may execute…

πŸ“… Published: June 25, 2024, 11:45 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS3.1

CVE-2024-29954 - password management API prints sensitive information in log files

A vulnerability in a password management API in Brocade Fabric OS versions before v9.2.1, v9.2.0b, v9.1.1d, and v8.2.3e prints sensitive information in log files. This could allow an authenticated user to view the server passwords for protocols such as scp and sftp. Detail. When the firmwaredownlo…

πŸ“… Published: June 25, 2024, 11:42 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:08 a.m.
Total resulsts: 349182
Page 9330 of 34,919
Β« previous page Β» next page
Filters