7.4

CVSS3.1

CVE-2024-34507 - mediawiki: cross-site scripting

An issue was discovered in includes/CommentFormatter/CommentParser.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. XSS can occur because of mishandling of the 0x1b character, as demonstrated by Special:RecentChanges#%1b0000000.

πŸ“… Published: May 5, 2024, midnight πŸ”„ Last Modified: Nov. 4, 2025, 6:16 p.m.

7.5

CVSS3.1

CVE-2024-34506 - mediawiki: denial of service

An issue was discovered in includes/specials/SpecialMovePage.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. If a user with the necessary rights to move the page opens Special:MovePage for a page with tens of thousands of subpages, then the page will exceed the maxim…

πŸ“… Published: May 5, 2024, midnight πŸ”„ Last Modified: Nov. 4, 2025, 6:16 p.m.

9.8

CVSS3.1

CVE-2024-34502 - mediawiki: MergeLexemes makes edits on GET requests without edit tokens

An issue was discovered in WikibaseLexeme in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. Loading Special:MergeLexemes will (attempt to) make an edit that merges the from-id to the to-id, even if the request was not a POST request, and even if it does not contain an edit…

πŸ“… Published: May 5, 2024, midnight πŸ”„ Last Modified: Nov. 4, 2025, 6:16 p.m.

6.1

CVSS3.1

CVE-2024-34500 - mediawiki: XSS through interface message in UnlinkedWikibase

An issue was discovered in the UnlinkedWikibase extension in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. XSS can occur through an interface message. Error messages (in the $err var) are not escaped before being passed to Html::rawElement() in the getError() function in …

πŸ“… Published: May 5, 2024, midnight πŸ”„ Last Modified: Nov. 4, 2025, 6:16 p.m.

7.5

CVSS3.1

CVE-2024-34487 -

OFPFlowStats in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via inst.length=0.

πŸ“… Published: May 5, 2024, midnight πŸ”„ Last Modified: April 15, 2025, 5:39 p.m.

4.3

CVSS3.1

CVE-2024-34508 -

dcmnet in DCMTK before 3.6.9 has a segmentation fault via an invalid DIMSE message.

πŸ“… Published: May 5, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 9:16 p.m.

4.8

CVSS3.1

CVE-2024-34529 -

Nebari through 2024.4.1 prints the temporary Keycloak root password.

πŸ“… Published: May 5, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-34484 -

OFPBucket in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via action.len=0.

πŸ“… Published: May 5, 2024, midnight πŸ”„ Last Modified: April 15, 2025, 5:40 p.m.

8.8

CVSS3.1

CVE-2024-34515 -

image-optimizer before 1.7.3 allows PHAR deserialization, e.g., the phar:// protocol in arguments to file_exists().

πŸ“… Published: May 5, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-34486 -

OFPPacketQueue in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via OFPQueueProp.len=0.

πŸ“… Published: May 5, 2024, midnight πŸ”„ Last Modified: April 15, 2025, 5:39 p.m.
Total resulsts: 349182
Page 9984 of 34,919
Β« previous page Β» next page
Filters