6.5

CVSS3.1

CVE-2024-32760 - NGINX HTTP/3 QUIC vulnerability

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 encoder instructions can cause NGINX worker processes to terminate or cause or other potential impact.

πŸ“… Published: May 29, 2024, midnight πŸ”„ Last Modified: Feb. 13, 2025, 5:52 p.m.

4.8

CVSS3.1

CVE-2024-31079 - NGINX HTTP/3 QUIC vulnerability

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate or causeΒ other potential impact. This attack requires that a request be specifically timed during the connection draining process, which the attacker …

πŸ“… Published: May 29, 2024, midnight πŸ”„ Last Modified: Feb. 13, 2025, 5:47 p.m.

8.1

CVSS3.1

CVE-2024-36427 -

The file-serving function in TARGIT Decision Suite before 24.06.19002 (TARGIT Decision Suite 2024 – June) allows authenticated attackers to read or write to server files via a crafted file request. This can allow code execution via a .xview file.

πŸ“… Published: May 29, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2024-36015 - ppdev: Add an error check in register_device

In the Linux kernel, the following vulnerability has been resolved: ppdev: Add an error check in register_device In register_device, the return value of ida_simple_get is unchecked, in witch ida_simple_get will use an invalid index value. To address this issue, index should be checked after ida_…

πŸ“… Published: May 29, 2024, midnight πŸ”„ Last Modified: Nov. 4, 2025, 6:16 p.m.

7.7

CVSS3.1

CVE-2024-36016 - tty: n_gsm: fix possible out-of-bounds in gsm0_receive()

In the Linux kernel, the following vulnerability has been resolved: tty: n_gsm: fix possible out-of-bounds in gsm0_receive() Assuming the following: - side A configures the n_gsm in basic option mode - side B sends the header of a basic option mode frame with data length 1 - side A switches to ad…

πŸ“… Published: May 29, 2024, midnight πŸ”„ Last Modified: Nov. 4, 2025, 6:16 p.m.

5.5

CVSS3.1

CVE-2024-36014 - drm/arm/malidp: fix a possible null pointer dereference

In the Linux kernel, the following vulnerability has been resolved: drm/arm/malidp: fix a possible null pointer dereference In malidp_mw_connector_reset, new memory is allocated with kzalloc, but no check is performed. In order to prevent null pointer dereferencing, ensure that mw_state is checke…

πŸ“… Published: May 29, 2024, midnight πŸ”„ Last Modified: Nov. 4, 2025, 6:16 p.m.

8.2

CVSS3.1

CVE-2024-21512 - mysql2: vulnerable to Prototype Pollution due to improper user input sanitization

Versions of the package mysql2 before 3.9.8 are vulnerable to Prototype Pollution due to improper user input sanitization passed to fields and tables when using nestTables.

πŸ“… Published: May 29, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-34161 - NGINX HTTP/3 QUIC vulnerability

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or greater without fragmentation, undisclosed QUIC packets can cause NGINX worker processes to leak previously freed memory.

πŸ“… Published: May 29, 2024, midnight πŸ”„ Last Modified: Feb. 13, 2025, 5:52 p.m.

5.3

CVSS4.0

CVE-2024-5437 - SourceCodester Simple Online Bidding System save_category cross site scripting

A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been classified as problematic. Affected is the function save_category of the file /admin/index.php?page=categories. The manipulation of the argument name leads to cross site scripting. It is possible to launch the…

πŸ“… Published: May 28, 2024, 11:31 p.m. πŸ”„ Last Modified: Dec. 9, 2024, 10:52 p.m.

6.3

CVSS3.1

CVE-2024-36112 - Nautobot dynamic-group-members doesn't enforce permission restrictions on member objects

Nautobot is a Network Source of Truth and Network Automation Platform. A user with permissions to view Dynamic Group records (`extras.view_dynamicgroup` permission) can use the Dynamic Group detail UI view (`/extras/dynamic-groups/<uuid>/`) and/or the members REST API view (`/api/extras/dynamic-gro…

πŸ“… Published: May 28, 2024, 10:26 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 4:21 p.m.
Total resulsts: 349182
Page 9646 of 34,919
Β« previous page Β» next page
Filters