6.9

CVSS4.0

CVE-2023-45195 - Adminer and AdminerEvo SSRF

Adminer and AdminerEvo are vulnerable to SSRF via database connection fields. This could allow an unauthenticated remote attacker to enumerate or access systems the attacker would not otherwise have access to.Β Adminer is no longer supported, but this issue was fixed in AdminerEvo version 4.8.4.

πŸ“… Published: June 24, 2024, 9:06 p.m. πŸ”„ Last Modified: Oct. 15, 2025, 3:32 p.m.

6.9

CVSS4.0

CVE-2023-45196 - Adminer and AdminerEvo denial of service via HTTP redirect

Adminer and AdminerEvo allow an unauthenticated remote attacker to cause a denial of service by connecting to an attacker-controlled service that responds with HTTP redirects. The denial of service is subject to PHP configuration limits.Β Adminer is no longer supported, but this issue was fixed in A…

πŸ“… Published: June 24, 2024, 8:48 p.m. πŸ”„ Last Modified: Oct. 15, 2025, 3:32 p.m.

6.5

CVSS3.1

CVE-2023-49793 - Path traversal in `CodeChecker server` in the endpoint of `CodeChecker store`

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Zip files uploaded to the server endpoint of `CodeChecker store` are not properly sanitized. An attacker, using a path traversal attack, can load and display files on the machine o…

πŸ“… Published: June 24, 2024, 5:36 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 8:33 a.m.

10

CVSS3.1

CVE-2024-38369 - XWiki programming rights may be inherited by inclusion

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The content of a document included using `{{include reference="targetdocument"/}}` is executed with the right of the includer and not with the right of its author. This means that any user able …

πŸ“… Published: June 24, 2024, 4:39 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:25 a.m.

9.6

CVSS3.1

CVE-2024-38373 - FreeRTOS-Plus-TCP Buffer Over-Read in DNS Response Parser

FreeRTOS-Plus-TCP is a lightweight TCP/IP stack for FreeRTOS. FreeRTOS-Plus-TCP versions 4.0.0 through 4.1.0 contain a buffer over-read issue in the DNS Response Parser when parsing domain names in a DNS response. A carefully crafted DNS response with domain name length value greater than the actua…

πŸ“… Published: June 24, 2024, 4:23 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:25 a.m.

7.5

CVSS3.1

CVE-2024-6287 - Incorrect Address Range Calculations

Incorrect Calculation vulnerability in Renesas arm-trusted-firmware allows Local Execution of Code. When checking whether a new image invades/overlaps with a previously loaded image the code neglects to consider a few cases. that could An attacker to bypass memory range restriction and overwrite …

πŸ“… Published: June 24, 2024, 3:37 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:49 a.m.

7.5

CVSS3.1

CVE-2024-6285 - Integer Underflow in Memory Range Check in Renesas RCAR

Integer Underflow (Wrap or Wraparound) vulnerability in Renesas arm-trusted-firmware. An integer underflow in image range check calculations could lead to bypassing address restrictions and loading of images to unallowed addresses.

πŸ“… Published: June 24, 2024, 3:32 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:49 a.m.

7.5

CVSS3.1

CVE-2024-33687 -

Insufficient verification of data authenticity issue exists in NJ Series CPU Unit all versions and NX Series CPU Unit all versions. If a user program in the affected product is altered, the product may not be able to detect the alteration.

πŸ“… Published: June 24, 2024, 3:03 p.m. πŸ”„ Last Modified: March 13, 2025, 3:15 p.m.

8.8

CVSS3.1

CVE-2024-4748 - RCE in Cruddiy

The CRUDDIY project is vulnerable to shell command injection via sending a crafted POST request to the application server.Β  The exploitation risk is limited since CRUDDIY is meant to be launched locally. Nevertheless, a user with the project running on their computer might visit a website which wou…

πŸ“… Published: June 24, 2024, 1:52 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:43 a.m.

3.3

CVSS3.1

CVE-2024-4839 - CSRF in Servers Configurations in parisneo/lollms-webui

A Cross-Site Request Forgery (CSRF) vulnerability exists in the 'Servers Configurations' function of the parisneo/lollms-webui, versions 9.6 to the latest. The affected functions include Elastic search Service (under construction), XTTS service, Petals service, vLLM service, and Motion Ctrl service…

πŸ“… Published: June 24, 2024, 12:47 p.m. πŸ”„ Last Modified: July 7, 2025, 5:31 p.m.
Total resulsts: 349182
Page 9346 of 34,919
Β« previous page Β» next page
Filters