Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2024-44797 |
|
Cross-Site Scripting (XSS) in gazelle-project (CVE-2024-44797)
cross-site scripting in gazelle-project (CVE-2024-44797). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-29929 |
|
Out-of-Bounds Write in dos (CVE-2023-29929)
out-of-bounds write in dos (CVE-2023-29929). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-6508 |
|
Vulnerability in csrf (CVE-2024-6508)
vulnerability in csrf (CVE-2024-6508). Successful exploitation can lead to full system takeover.
|
| CVE-2021-31196 KEV |
|
[KEV] Vulnerability in Microsoft exchange-server (CVE-2021-31196)
vulnerability in Microsoft exchange-server (CVE-2021-31196). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2024-42849 |
|
Vulnerability in dos (CVE-2024-42849)
vulnerability in dos (CVE-2024-42849). Risk of unauthorized operations or information disclosure.
|
| CVE-2022-23817 |
|
Vulnerability in privilege-escalation (CVE-2022-23817)
vulnerability in privilege-escalation (CVE-2022-23817). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-31339 |
|
Vulnerability in dos (CVE-2023-31339)
vulnerability in dos (CVE-2023-31339). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-6684 |
|
Vulnerability in CVE-2024-6684 (CVE-2024-6684)
vulnerability in CVE-2024-6684 (CVE-2024-6684). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-42467 |
|
SSRF (Server-Side Request Forgery) in org.openhab.ui.bundles:org.openhab.ui.cometvisu (CVE-2024-42467)
SSRF in org.openhab.ui.bundles:org.openhab.ui.cometvisu (CVE-2024-42467). Confidential information can be exposed externally. Mitigation: upgrade to `4.2.1` or later.
|
| CVE-2024-43112 |
|
Cross-Site Scripting (XSS) in mozilla (CVE-2024-43112)
cross-site scripting in mozilla (CVE-2024-43112). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-43113 |
|
Cross-Site Scripting (XSS) in mozilla (CVE-2024-43113)
cross-site scripting in mozilla (CVE-2024-43113). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-40101 |
|
Cross-Site Scripting (XSS) in microweber (CVE-2024-40101)
cross-site scripting in microweber (CVE-2024-40101). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-38889 |
|
SQL Injection in sqli (CVE-2024-38889)
SQL injection in sqli (CVE-2024-38889). Successful exploitation can lead to full system takeover.
|
| CVE-2024-38882 |
|
OS Command Injection in sqli (CVE-2024-38882)
OS command injection in sqli (CVE-2024-38882). Successful exploitation can lead to full system takeover.
|
| CVE-2024-38884 |
|
Authorization Flaw in horizoncloud (CVE-2024-38884)
vulnerability in horizoncloud (CVE-2024-38884). Successful exploitation can lead to full system takeover.
|
| CVE-2024-37129 |
|
Path Traversal in path-traversal (CVE-2024-37129)
path traversal in path-traversal (CVE-2024-37129). Successful exploitation can lead to full system takeover.
|
| CVE-2024-39011 |
|
Vulnerability in dos (CVE-2024-39011)
vulnerability in dos (CVE-2024-39011). Successful exploitation can lead to full system takeover.
|
| CVE-2024-38909 |
|
Vulnerability in std42 (CVE-2024-38909)
vulnerability in std42 (CVE-2024-38909). Successful exploitation can lead to full system takeover.
|
| CVE-2024-6699 |
|
SQL Injection in sqli (CVE-2024-6699)
SQL injection in sqli (CVE-2024-6699). Successful exploitation can lead to full system takeover.
|
| CVE-2024-37857 |
|
SQL Injection in sqli (CVE-2024-37857)
SQL injection in sqli (CVE-2024-37857). Successful exploitation can lead to full system takeover.
|
| CVE-2024-37858 |
|
SQL Injection in sqli (CVE-2024-37858)
SQL injection in sqli (CVE-2024-37858). Successful exploitation can lead to full system takeover.
|
| CVE-2024-37856 |
|
Cross-Site Scripting (XSS) in oretnom23 (CVE-2024-37856)
cross-site scripting in oretnom23 (CVE-2024-37856). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-37859 |
|
Cross-Site Scripting (XSS) in oretnom23 (CVE-2024-37859)
cross-site scripting in oretnom23 (CVE-2024-37859). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-41628 |
|
Path Traversal in path-traversal (CVE-2024-41628)
path traversal in path-traversal (CVE-2024-41628). Confidential information can be exposed externally.
|
| CVE-2024-41597 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2024-41597)
vulnerability in csrf (CVE-2024-41597). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-21527 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2024-21527)
SSRF in ssrf (CVE-2024-21527). Confidential information can be exposed externally.
|
| CVE-2024-0857 |
|
SQL Injection in sqli (CVE-2024-0857)
SQL injection in sqli (CVE-2024-0857). Successful exploitation can lead to full system takeover.
|
| CVE-2024-5620 |
|
Vulnerability in CVE-2024-5620 (CVE-2024-5620)
vulnerability in CVE-2024-5620 (CVE-2024-5620). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-4944 |
|
Command Injection in privilege-escalation (CVE-2024-4944)
command injection in privilege-escalation (CVE-2024-4944). Successful exploitation can lead to full system takeover.
|
| CVE-2024-5974 |
|
A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with...
A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with...
|
| CVE-2024-5971 |
|
A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers and body were sent but the client would continue waiting as Undertow does not s...
A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers and body were sent but the client would continue waiting as Undertow does not send the expected 0\r\n termination of the chunked response. This results in uncontrolled resource co...
|
| CVE-2024-6409 |
|
Vulnerability in CVE-2024-6409 (CVE-2024-6409)
vulnerability in CVE-2024-6409 (CVE-2024-6409). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-6127 |
|
Path Traversal in path-traversal (CVE-2024-6127)
path traversal in path-traversal (CVE-2024-6127). Successful exploitation can lead to full system takeover.
|
| CVE-2024-1153 |
|
SQL Injection in sqli (CVE-2024-1153)
SQL injection in sqli (CVE-2024-1153). Confidential information can be exposed externally.
|
| CVE-2024-0949 |
|
Vulnerability in CVE-2024-0949 (CVE-2024-0949)
vulnerability in CVE-2024-0949 (CVE-2024-0949). Successful exploitation can lead to full system takeover.
|
| CVE-2024-4228 |
|
SQL Injection in sqli (CVE-2024-4228)
SQL injection in sqli (CVE-2024-4228). Successful exploitation can lead to full system takeover.
|
| CVE-2024-4754 |
|
Cross-Site Scripting (XSS) in CVE-2024-4754 (CVE-2024-4754)
cross-site scripting in CVE-2024-4754 (CVE-2024-4754). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-37673 |
|
Cross-Site Scripting (XSS) in tessi (CVE-2024-37673)
cross-site scripting in tessi (CVE-2024-37673). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-37675 |
|
Cross-Site Scripting (XSS) in tessi (CVE-2024-37675)
cross-site scripting in tessi (CVE-2024-37675). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-37671 |
|
Cross-Site Scripting (XSS) in tessi (CVE-2024-37671)
cross-site scripting in tessi (CVE-2024-37671). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-37672 |
|
Cross-Site Scripting (XSS) in tessi (CVE-2024-37672)
cross-site scripting in tessi (CVE-2024-37672). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-37674 |
|
Cross-Site Scripting (XSS) in moodle (CVE-2024-37674)
cross-site scripting in moodle (CVE-2024-37674). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-5154 |
|
Path Traversal in github.com/cri-o/cri-o (CVE-2024-5154)
path traversal in github.com/cri-o/cri-o (CVE-2024-5154). Confidential information can be exposed externally. Mitigation: upgrade to `1.30.1` or later.
|
| CVE-2024-35249 |
|
Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability
Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability
|
| CVE-2024-35252 |
|
Azure Storage Movement Client Library Denial of Service Vulnerability
Azure Storage Movement Client Library Denial of Service Vulnerability
|
| CVE-2024-30104 |
|
Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
|
| CVE-2024-30101 |
|
Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
|
| CVE-2024-30103 |
|
Microsoft Outlook Remote Code Execution Vulnerability
Microsoft Outlook Remote Code Execution Vulnerability
|
| CVE-2024-30095 |
|
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
|
| CVE-2024-30097 |
|
Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability
Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability
|