7.5

CVSS3.1

CVE-2025-21620 - Deno's authorization headers not dropped when redirecting cross-origin

Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. When you send a request with the Authorization header to one domain, and the response asks to redirect to a different domain, Deno'sfetch() redirect handling creates a follow-up redirect request that keeps the original …

πŸ“… Published: Jan. 6, 2025, 10:26 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-21616 - Plane has a Cross-site scripting (XSS) via SVG image upload

Plane is an open-source project management tool. A cross-site scripting (XSS) vulnerability has been identified in Plane versions prior to 0.23. The vulnerability allows authenticated users to upload SVG files containing malicious JavaScript code as profile images, which gets executed in victims' b…

πŸ“… Published: Jan. 6, 2025, 9:22 p.m. πŸ”„ Last Modified: June 20, 2025, 6:08 p.m.

4.4

CVSS3.1

CVE-2024-51741 - Redis allows denial-of-service due to malformed ACL selectors

Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, triggers a server panic and subsequent denial of service. The problem is fixed in Redis 7.2.7 and 7.4.2.

πŸ“… Published: Jan. 6, 2025, 9:20 p.m. πŸ”„ Last Modified: Sept. 5, 2025, 2:25 p.m.

7

CVSS3.1

CVE-2024-46981 - Redis' Lua library commands may lead to remote code execution

Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to manipulate the garbage collector and potentially lead to remote code execution. The problem is fixed in 7.4.2, 7.2.7, and 6.2.17. An additional workaround to mitigate t…

πŸ“… Published: Jan. 6, 2025, 9:11 p.m. πŸ”„ Last Modified: Sept. 5, 2025, 2:20 p.m.

0.0

CVE-2024-13154 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: 2024-13362. Reason: This candidate is a reservation duplicate of 2024-13362. Notes: All CVE users should reference 2024-13362 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accident…

πŸ“… Published: Jan. 6, 2025, 8:19 p.m. πŸ”„ Last Modified: Jan. 13, 2025, 9:15 p.m.

6.3

CVSS4.0

CVE-2025-21617 - Guzzle OAuth Subscriber has insufficient nonce entropy

Guzzle OAuth Subscriber signs Guzzle requests using OAuth 1.0. Prior to 0.8.1, Nonce generation does not use sufficient entropy nor a cryptographically secure pseudorandom source. This can leave servers vulnerable to replay attacks when TLS is not used. This vulnerability is fixed in 0.8.1.

πŸ“… Published: Jan. 6, 2025, 7:23 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-55629 - Suricata generic detection bypass using TCP urgent support

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.8, TCP streams with TCP urgent data (out of band data) can lead to Suricata analyzing data differently than the applications at the TCP endpoints, leading to possible e…

πŸ“… Published: Jan. 6, 2025, 6:04 p.m. πŸ”„ Last Modified: March 31, 2025, 12:54 p.m.

7.5

CVSS3.1

CVE-2024-55628 - Suricata oversized resource names utilizing DNS name compression can lead to resource starvation

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.8, DNS resource name compression can lead to small DNS messages containing very large hostnames which can be costly to decode, and lead to very large DNS log re…

πŸ“… Published: Jan. 6, 2025, 6:02 p.m. πŸ”„ Last Modified: March 31, 2025, 1:02 p.m.

5.9

CVSS3.1

CVE-2024-55627 - Suricata segfault on StreamingBufferSlideToOffsetWithRegions

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.8, a specially crafted TCP stream can lead to a very large buffer overflow while being zero-filled during initialization with memset due to an unsigned integer underflo…

πŸ“… Published: Jan. 6, 2025, 5:50 p.m. πŸ”„ Last Modified: March 31, 2025, 1:40 p.m.

3.3

CVSS3.1

CVE-2024-55626 - Suricata oversized bpf file can lead to buffer overflow

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.8, a large BPF filter file provided to Suricata at startup can lead to a buffer overflow at Suricata startup. The issue has been addressed in Suricata 7.0.8.

πŸ“… Published: Jan. 6, 2025, 5:47 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 8:16 p.m.
Total resulsts: 346619
Page 7014 of 34,662
Β« previous page Β» next page
Filters