8.8

CVSS3.1

CVE-2023-49222 -

Precor touchscreen console P82 contains a private SSH key that corresponds to a default public key. A remote attacker could exploit this to gain root privileges.

๐Ÿ“… Published: June 7, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-30163 -

Invision Community before 4.7.16 allow SQL injection via the applications/nexus/modules/front/store/store.php IPS\nexus\modules\front\store\_store::_categoryView() method, where user input passed through the filter request parameter is not properly sanitized before being used to execute SQL queriesโ€ฆ

๐Ÿ“… Published: June 7, 2024, midnight ๐Ÿ”„ Last Modified: March 19, 2025, 5:15 p.m.

6.1

CVSS3.1

CVE-2024-37383 - roundcubemail: allows XSS via SVG animate attributes

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.

๐Ÿ“… Published: June 7, 2024, midnight ๐Ÿ”„ Last Modified: Oct. 31, 2025, 12:48 p.m.

8.4

CVSS3.1

CVE-2024-31959 -

An issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks a check for the validation of native handles, which can result in code execution.

๐Ÿ“… Published: June 7, 2024, midnight ๐Ÿ”„ Last Modified: June 26, 2025, 8:40 p.m.

9.8

CVSS3.1

CVE-2024-4577 - Argument Injection in PHP-CGI

In PHP versionsย 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given toย Win32 API functions. PHP CGI module may misinโ€ฆ

๐Ÿ“… Published: June 7, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 3, 2025, 7:23 p.m.

4.9

CVSS3.1

CVE-2024-37280 - Elasticsearch StackOverflow vulnerability

A flaw was discovered in Elasticsearch, affecting document ingestion when an index template contains a dynamic field mapping of โ€œpassthroughโ€ type. Under certain circumstances, ingesting documents in this index would cause a StackOverflow exception to be thrown and ultimately lead to a Denial of Seโ€ฆ

๐Ÿ“… Published: June 7, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:23 a.m.

9.1

CVSS3.1

CVE-2024-37388 -

An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of lxml before v4.9.1 allows attackers to access sensitive information or cause a Denial of Service (DoS) via crafted XML input.

๐Ÿ“… Published: June 7, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:23 a.m.

7.2

CVSS3.1

CVE-2024-30162 -

Invision Community through 4.7.16 allows remote code execution via the applications/core/modules/admin/editor/toolbar.php IPS\core\modules\admin\editor\_toolbar::addPlugin() method. This method handles uploaded ZIP files that are extracted into the applications/core/interface/ckeditor/ckeditor/plugโ€ฆ

๐Ÿ“… Published: June 7, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS3.1

CVE-2024-2408 - PHP is vulnerable to the Marvin Attack

The openssl_private_decrypt function in PHP, when using PKCS1 padding (OPENSSL_PKCS1_PADDING, which is the default), is vulnerable to the Marvin Attack unless it is used with an OpenSSL version that includes the changes from this pull request: https://github.com/openssl/openssl/pull/13817 (rsa_pkโ€ฆ

๐Ÿ“… Published: June 7, 2024, midnight ๐Ÿ”„ Last Modified: March 21, 2025, 6:15 p.m.

6.1

CVSS3.1

CVE-2024-37384 -

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences.

๐Ÿ“… Published: June 7, 2024, midnight ๐Ÿ”„ Last Modified: May 1, 2025, 7:51 p.m.
Total resulsts: 349182
Page 9555 of 34,919
ยซ previous page ยป next page
Filters