5.5

CVSS3.1

CVE-2022-28652 -

~/.config/apport/settings parsing is vulnerable to "billion laughs" attack

๐Ÿ“… Published: June 4, 2024, 9:38 p.m. ๐Ÿ”„ Last Modified: March 13, 2025, 7:15 p.m.

9.1

CVSS3.1

CVE-2024-36675 -

LyLme_spage v1.9.5 is vulnerable to Server-Side Request Forgery (SSRF) via the get_head function.

๐Ÿ“… Published: June 4, 2024, 9:31 p.m. ๐Ÿ”„ Last Modified: Feb. 13, 2025, 3:59 p.m.

5.9

CVSS3.1

CVE-2024-36121 - netty-incubator-codec-ohttp's BoringSSLAEADContext Repeats Nonces

netty-incubator-codec-ohttp is the OHTTP implementation for netty. BoringSSLAEADContext keeps track of how many OHTTP responses have been sent and uses this sequence number to calculate the appropriate nonce to use with the encryption algorithm. Unfortunately, two separate errors combine which wouโ€ฆ

๐Ÿ“… Published: June 4, 2024, 9:13 p.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:21 a.m.

4.3

CVSS3.1

CVE-2024-4220 - Information Disclosure in BeyondInsight

Prior to 23.1, an information disclosure vulnerability exists within BeyondInsight which can allow an attacker to enumerate usernames.

๐Ÿ“… Published: June 4, 2024, 8:13 p.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:42 a.m.

4.8

CVSS3.1

CVE-2024-4219 - SSRF In BeyondInsight

Prior to 23.2, it is possible to perform arbitrary Server-Side requests via HTTP-based connectors within BeyondInsight, resulting in a server-side request forgery vulnerability.

๐Ÿ“… Published: June 4, 2024, 8:08 p.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:42 a.m.

6.1

CVSS3.1

CVE-2024-32464 - ActionText ContentAttachment can Contain Unsanitized HTML

Action Text brings rich text content and editing to Rails. Instances of ActionText::Attachable::ContentAttachment included within a rich_text_area tag could potentially contain unsanitized HTML. This vulnerability is fixed in 7.1.3.4 and 7.2.0.beta2.

๐Ÿ“… Published: June 4, 2024, 7:53 p.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:14 a.m.

7.5

CVSS3.1

CVE-2024-4520 - Improper Access Control in gaizhenbiao/chuanhuchatgpt

An improper access control vulnerability exists in the gaizhenbiao/chuanhuchatgpt application, specifically in version 20240410. This vulnerability allows any user on the server to access the chat history of any other user without requiring any form of interaction between the users. Exploitation ofโ€ฆ

๐Ÿ“… Published: June 4, 2024, 7:40 p.m. ๐Ÿ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

5.3

CVSS3.1

CVE-2024-30525 - WordPress Move Addons for Elementor plugin <= 1.2.9 - Broken Access Control vulnerability

Missing Authorization vulnerability in moveaddons Move Addons for Elementor.This issue affects Move Addons for Elementor: from n/a through 1.2.9.

๐Ÿ“… Published: June 4, 2024, 7:24 p.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:12 a.m.

5.4

CVSS3.1

CVE-2024-30528 - WordPress Spiffy Calendar plugin <= 4.9.10 - Broken Access Control vulnerability

Missing Authorization vulnerability in Spiffy Plugins Spiffy Calendar.This issue affects Spiffy Calendar: from n/a through 4.9.10.

๐Ÿ“… Published: June 4, 2024, 7:19 p.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:12 a.m.

4.3

CVSS3.1

CVE-2024-30484 - WordPress RT Easy Builder plugin <= 2.0 - Broken Access Control vulnerability

Missing Authorization vulnerability in RT Easy Builder โ€“ Advanced addons for Elementor.This issue affects RT Easy Builder โ€“ Advanced addons for Elementor: from n/a through 2.0.

๐Ÿ“… Published: June 4, 2024, 7:08 p.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:12 a.m.
Total resulsts: 349182
Page 9582 of 34,919
ยซ previous page ยป next page
Filters