6.5

CVSS3.1

CVE-2024-37632 -

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via the password parameter in function loginAuth .

πŸ“… Published: June 13, 2024, midnight πŸ”„ Last Modified: March 13, 2025, 6:15 p.m.

4.5

CVSS3.1

CVE-2023-52890 -

NTFS-3G before 75dcdc2 has a use-after-free in ntfs_uppercase_mbs in libntfs-3g/unistr.c. NOTE: discussion suggests that exploitation would be challenging.

πŸ“… Published: June 13, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2023-35860 -

A Directory Traversal vulnerability in Modern Campus - Omni CMS 2023.1 allows a remote, unauthenticated attacker to enumerate file system information via the dir parameter to listing.php or rss.php.

πŸ“… Published: June 13, 2024, midnight πŸ”„ Last Modified: Nov. 21, 2024, 8:08 a.m.

7.5

CVSS3.1

CVE-2024-36760 -

A stack overflow vulnerability was found in version 1.18.0 of rhai. The flaw position is: (/ SRC/rhai/SRC/eval/STMT. Rs in rhai: : eval: : STMT: : _ $LT $impl $u20 $rhai.. engine.. Engine$GT$::eval_stmt::h3f1d68ce37fc6e96). Due to the stack overflow is a recursive call/SRC/rhai/SRC/eval/STMT. Rs fi…

πŸ“… Published: June 13, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.7

CVSS3.1

CVE-2024-5967 - Keycloak: leak of configured ldap bind credentials through the keycloak admin console

A vulnerability was found in Keycloak. The LDAP testing endpoint allows changing the Connection URLΒ  independently without re-entering the currently configured LDAP bind credentials. This flaw allows an attacker with adminΒ access (permission manage-realm) to change the LDAP host URL ("Connection UR…

πŸ“… Published: June 13, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-35325 - libyaml: double-free in yaml_event_delete in /src/libyaml/src/api.c

DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

πŸ“… Published: June 13, 2024, midnight πŸ”„ Last Modified: Aug. 28, 2024, 4:15 p.m.

6.5

CVSS3.1

CVE-2024-36588 -

An issue in Annonshop.app DecentralizeJustice/ anonymousLocker commit 2b2b4 allows attackers to send messages erroneously attributed to arbitrary users via a crafted HTTP request.

πŸ“… Published: June 13, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-1736 - Uncontrolled Resource Consumption in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting from 17.0 prior to 17.0.2. A vulnerability in GitLab's CI/CD pipeline editor could allow for denial of service attacks through maliciously crafted configuration f…

πŸ“… Published: June 12, 2024, 11:02 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 8:51 a.m.

6.5

CVSS3.1

CVE-2024-1495 - Uncontrolled Resource Consumption in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.1 prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting from 17.0 prior to 17.0.2. It was possible for an attacker to cause a denial of service using maliciously crafted file.

πŸ“… Published: June 12, 2024, 11:02 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 8:50 a.m.

6.5

CVSS3.1

CVE-2024-1963 - Uncontrolled Resource Consumption in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.4 prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting from 17.0 prior to 17.0.2. A vulnerability in GitLab's Asana integration allowed an attacker to potentially cause a regular expression denial of…

πŸ“… Published: June 12, 2024, 11:02 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 8:51 a.m.
Total resulsts: 349182
Page 9479 of 34,919
Β« previous page Β» next page
Filters