7.5

CVSS3.1

CVE-2024-36611 -

In Symfony v7.07, a security vulnerability was identified in the FormLoginAuthenticator component, where it failed to adequately handle cases where the username or password field of a login request is empty. This flaw could lead to various security risks, including improper authentication logic han…

πŸ“… Published: Nov. 29, 2024, midnight πŸ”„ Last Modified: Jan. 6, 2025, 5:44 p.m.

9.8

CVSS3.1

CVE-2024-36671 -

nodemcu before v3.0.0-release_20240225 was discovered to contain an integer overflow via the getnum function at /modules/struct.c.

πŸ“… Published: Nov. 29, 2024, midnight πŸ”„ Last Modified: Dec. 4, 2024, 5:15 p.m.

9.8

CVSS3.1

CVE-2024-36622 -

In RaspAP raspap-webgui 3.0.9 and earlier, a command injection vulnerability exists in the clearlog.php script. The vulnerability is due to improper sanitization of user input passed via the logfile parameter.

πŸ“… Published: Nov. 29, 2024, midnight πŸ”„ Last Modified: July 2, 2025, 8:41 p.m.

9.8

CVSS3.1

CVE-2024-52780 -

DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code Execution via /function/system/basic/mgmt_edit.php.

πŸ“… Published: Nov. 29, 2024, midnight πŸ”„ Last Modified: Nov. 6, 2025, 9:08 p.m.

4.8

CVSS3.1

CVE-2024-35451 -

LinkStack 2.7.9 through 4.7.7 allows resources\views\components\favicon.blade.php link SSRF.

πŸ“… Published: Nov. 29, 2024, midnight πŸ”„ Last Modified: July 3, 2025, 12:31 a.m.

6.1

CVSS3.1

CVE-2024-36625 -

Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the replace_emoji_with_text function in ui_util.ts.

πŸ“… Published: Nov. 29, 2024, midnight πŸ”„ Last Modified: Nov. 25, 2025, 1:50 p.m.

6.2

CVSS3.1

CVE-2024-36617 -

FFmpeg n6.1.1 has an integer overflow vulnerability in the FFmpeg CAF decoder.

πŸ“… Published: Nov. 29, 2024, midnight πŸ”„ Last Modified: June 3, 2025, 6:06 p.m.

9.8

CVSS3.1

CVE-2024-48406 -

Buffer Overflow vulnerability in SunBK201 umicat through v.0.3.2 and fixed in v.0.3.3 allows an attacker to execute arbitrary code via the power(uct_int_t x, uct_int_t n) in src/uct_upstream.c.

πŸ“… Published: Nov. 29, 2024, midnight πŸ”„ Last Modified: Dec. 4, 2024, 5:15 p.m.

9.8

CVSS3.1

CVE-2024-52782 -

DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code Execution via /function/audit/newstatistics/mon_stat_hist_new.php.

πŸ“… Published: Nov. 29, 2024, midnight πŸ”„ Last Modified: Nov. 6, 2025, 8:57 p.m.

6.1

CVSS3.1

CVE-2024-39162 -

pyspider through 0.3.10 allows /update XSS. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

πŸ“… Published: Nov. 29, 2024, midnight πŸ”„ Last Modified: Nov. 29, 2024, 3:15 p.m.
Total resulsts: 343974
Page 7151 of 34,398
Β« previous page Β» next page
Filters