7.5

CVSS3.1

CVE-2024-24195 -

robdns commit d76d2e6 was discovered to contain a misaligned address at /src/zonefile-insertion.c.

πŸ“… Published: June 6, 2024, 9:24 p.m. πŸ”„ Last Modified: Feb. 13, 2025, 3:47 p.m.

7.5

CVSS3.1

CVE-2024-24194 -

robdns commit d76d2e6 was discovered to contain a NULL pointer dereference via the item->tokens component at /src/conf-parse.c.

πŸ“… Published: June 6, 2024, 9:23 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.7

CVSS3.1

CVE-2024-24192 -

robdns commit d76d2e6 was discovered to contain a heap overflow via the component block->filename at /src/zonefile-insertion.c.

πŸ“… Published: June 6, 2024, 9:23 p.m. πŸ”„ Last Modified: Feb. 13, 2025, 3:47 p.m.

7.5

CVSS3.1

CVE-2024-36823 -

The encrypt() function of Ninja Core v7.0.0 was discovered to use a weak cryptographic algorithm, leading to a possible leakage of sensitive information.

πŸ“… Published: June 6, 2024, 9:14 p.m. πŸ”„ Last Modified: March 25, 2025, 7:15 p.m.

8.8

CVSS4.0

CVE-2024-32752 - Johnson Controls Software House iSTAR Configuration Utility (ICU) Tool

The iSTAR door controllers running firmware prior to version 6.6.B, does not support authenticated communications with ICU, which may allow an attacker to gain unauthorized access

πŸ“… Published: June 6, 2024, 8:49 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.0

CVSS3.1

CVE-2024-36795 -

Insecure permissions in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to access URLs and directories embedded within the firmware via unspecified vectors.

πŸ“… Published: June 6, 2024, 8:49 p.m. πŸ”„ Last Modified: May 29, 2025, 4:14 p.m.

9.8

CVSS3.1

CVE-2024-22074 -

Dynamsoft Service 1.8.1025 through 1.8.2013, 1.7.0330 through 1.7.2531, 1.6.0428 through 1.6.1112, 1.5.0625 through 1.5.3116, 1.4.0618 through 1.4.1230, and 1.0.516 through 1.3.0115 has Incorrect Access Control. This is fixed in 1.8.2014, 1.7.4212, 1.6.3212, 1.5.31212, 1.4.3212, and 1.3.3212.

πŸ“… Published: June 6, 2024, 8:45 p.m. πŸ”„ Last Modified: March 18, 2025, 9:15 p.m.

7.5

CVSS3.1

CVE-2024-36730 -

Improper input validation in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputting negative values into the oneflow.zeros/ones parameter.

πŸ“… Published: June 6, 2024, 7:06 p.m. πŸ”„ Last Modified: March 14, 2025, 2:15 p.m.

5.3

CVSS3.1

CVE-2024-37154 - Evmos allows unvested token delegations

Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. Users are able to delegate tokens that have not yet been vested. This affects employees and grantees who have funds managed via `ClawbackVestingAccount`. This affects 18.1.0 and earlier.

πŸ“… Published: June 6, 2024, 7:04 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:23 a.m.

9.8

CVSS3.1

CVE-2024-2359 - Improper Neutralization of Special Elements used in an OS Command in parisneo/lollms-webui

A vulnerability in the parisneo/lollms-webui version 9.3 allows attackers to bypass intended access restrictions and execute arbitrary code. The issue arises from the application's handling of the `/execute_code` endpoint, which is intended to be blocked from external access by default. However, at…

πŸ“… Published: June 6, 2024, 6:55 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:09 a.m.
Total resulsts: 349182
Page 9557 of 34,919
Β« previous page Β» next page
Filters