7.7

CVSS3.1

CVE-2024-5585 - Command injection via array-ish $command parameter of proc_open() (bypass CVE-2024-1874 fix)

In PHP versionsย 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, the fix forย CVE-2024-1874 does not work if the command name includes trailing spaces. Original issue:ย when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed commanโ€ฆ

๐Ÿ“… Published: June 7, 2024, midnight ๐Ÿ”„ Last Modified: Feb. 13, 2025, 5:54 p.m.

8.4

CVSS3.1

CVE-2023-37539 - HCL Domino Catalog template is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability

The Domino Catalog template is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. An attacker with the ability to edit documents in the catalog application/database created from this template can embed a cross site scripting attack. The attack would be activated by an end user clickโ€ฆ

๐Ÿ“… Published: June 6, 2024, 10:43 p.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 8:11 a.m.

4.7

CVSS3.1

CVE-2024-36775 -

A cross-site scripting (XSS) vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the About Me parameter in the Edit Profile page.

๐Ÿ“… Published: June 6, 2024, 9:35 p.m. ๐Ÿ”„ Last Modified: Feb. 13, 2025, 3:59 p.m.

7.2

CVSS3.1

CVE-2024-36774 -

An arbitrary file upload vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary code via uploading a crafted PHP file.

๐Ÿ“… Published: June 6, 2024, 9:33 p.m. ๐Ÿ”„ Last Modified: Feb. 13, 2025, 3:59 p.m.

5.6

CVSS3.1

CVE-2024-4013 - Failure to update BT Mesh Replay Protection List

A bug exists in the API, mesh_node_power_off(), which fails to copy the contents of the Replay Protection List (RPL) from RAM to NVM before powering down, resulting in the ability to replay unsaved messages. Note that as of June 2024, the Gecko SDK was renamed to the Simplicity SDK, and the versioโ€ฆ

๐Ÿ“… Published: June 6, 2024, 9:31 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2023-51847 -

An issue in obgm and Libcoap v.a3ed466 allows a remote attacker to cause a denial of service via thecoap_context_t function in the src/coap_threadsafe.c:297:3 component.

๐Ÿ“… Published: June 6, 2024, 9:31 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2024-22525 -

dnspod-sr 0dfbd37 contains a SEGV.

๐Ÿ“… Published: June 6, 2024, 9:29 p.m. ๐Ÿ”„ Last Modified: March 18, 2025, 4:15 p.m.

5.5

CVSS3.1

CVE-2024-22524 -

dnspod-sr 0dfbd37 is vulnerable to buffer overflow.

๐Ÿ“… Published: June 6, 2024, 9:28 p.m. ๐Ÿ”„ Last Modified: March 27, 2025, 9:15 p.m.

7.5

CVSS3.1

CVE-2024-24199 -

smartdns commit 54b4dc was discovered to contain a misaligned address at smartdns/src/dns.c.

๐Ÿ“… Published: June 6, 2024, 9:27 p.m. ๐Ÿ”„ Last Modified: March 13, 2025, 2:15 p.m.

7.5

CVSS3.1

CVE-2024-24198 -

smartdns commit 54b4dc was discovered to contain a misaligned address at smartdns/src/util.c.

๐Ÿ“… Published: June 6, 2024, 9:26 p.m. ๐Ÿ”„ Last Modified: Feb. 13, 2025, 3:47 p.m.
Total resulsts: 349182
Page 9556 of 34,919
ยซ previous page ยป next page
Filters