CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2024-39015

    Last Modified: 15 Apr 2026

    cafebazaar hod v0.4.14 was discovered to contain a prototype pollution via the function request. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

    Published: 1 Jul 2024
    9.8
    Critical

    CVE-2024-39014

    Last Modified: 15 Apr 2026

    ahilfoley cahil/utils v2.3.2 was discovered to contain a prototype pollution via the function set. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

    Published: 1 Jul 2024
    9.8
    Critical

    CVE-2024-39013

    Last Modified: 15 Apr 2026

    2o3t-utility v0.1.2 was discovered to contain a prototype pollution via the function extend. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

    Published: 1 Jul 2024
    10
    Critical

    CVE-2024-39008

    Last Modified: 15 Apr 2026

    robinweser fast-loops v1.1.3 was discovered to contain a prototype pollution via the function objectMergeDeep. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

    Published: 1 Jul 2024
    8.8
    High

    CVE-2024-23736

    Last Modified: 15 Apr 2026

    Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Confluence allows attackers to manipulate a user's S/MIME certificate of PGP key via malicious link or email.

    Published: 1 Jul 2024
    9.1
    Critical

    CVE-2024-38475

    Last Modified: 17 Nov 2025

    Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure. Substitutions in server context that use a backreferences or variables as the first segment of the substitution are affected.  Some unsafe RewiteRules will be broken by this change and the rewrite flag "UnsafePrefixStat" can be used to opt back in once ensuring the substitution is appropriately constrained.

    Published: 1 Jul 2024
    6.5
    Medium

    CVE-2024-39853

    Last Modified: 10 Jul 2025

    adolph_dudu ratio-swiper 0.0.2 was discovered to contain a prototype pollution via the function parse. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

    Published: 1 Jul 2024
    10
    Critical

    CVE-2024-39251

    Last Modified: 15 Apr 2026

    An issue in the component ControlCenter.sys/ControlCenter64.sys of ThundeRobot Control Center v2.0.0.10 allows attackers to access sensitive information, execute arbitrary code, or escalate privileges via sending crafted IOCTL requests.

    Published: 1 Jul 2024
    9.9
    Critical

    CVE-2024-37762

    Last Modified: 30 Apr 2025

    MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution.

    Published: 1 Jul 2024
    9.8
    Critical

    CVE-2024-38474

    Last Modified: 25 Mar 2025

    Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version 2.4.60, which fixes this issue. Some RewriteRules that capture and substitute unsafely will now fail unless rewrite flag "UnsafeAllow3F" is specified.

    Published: 1 Jul 2024
    6.1
    Medium

    CVE-2024-38953

    Last Modified: 20 Mar 2025

    phpok 6.4.003 contains a Cross Site Scripting (XSS) vulnerability in the ok_f() method under the framework/api/upload_control.php file.

    Published: 1 Jul 2024
    6.5
    Medium

    CVE-2024-38997

    Last Modified: 7 Jul 2025

    adolph_dudu ratio-swiper v0.0.2 was discovered to contain a prototype pollution via the function extendDefaults. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

    Published: 1 Jul 2024
    6.3
    Medium

    CVE-2024-39001

    Last Modified: 1 May 2025

    ag-grid-enterprise v31.3.2 was discovered to contain a prototype pollution via the component _ModuleSupport.jsonApply. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

    Published: 1 Jul 2024
    7.3
    High

    CVE-2024-39003

    Last Modified: 7 Jul 2025

    amoyjs amoy common v1.0.10 was discovered to contain a prototype pollution via the function setValue. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

    Published: 1 Jul 2024
    6.3
    Medium

    CVE-2024-38987

    Last Modified: 15 Apr 2026

    aofl cli-lib v3.14.0 was discovered to contain a prototype pollution via the component defaultsDeep. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

    Published: 1 Jul 2024
    5.4
    Medium

    CVE-2024-36387

    Last Modified: 6 Nov 2025

    Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.

    Published: 1 Jul 2024
    5.4
    Medium

    CVE-2024-23737

    Last Modified: 18 Mar 2025

    Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Jira allows attackers to allows attackers to manipulate a user's S/MIME certificate of PGP key via malicious link or email.

    Published: 1 Jul 2024
    8.4
    High

    CVE-2024-32229

    Last Modified: 3 Jun 2025

    FFmpeg 7.0 contains a heap-buffer-overflow at libavfilter/vf_tiltandshift.c:189:5 in copy_column.

    Published: 1 Jul 2024
    6.6
    Medium

    CVE-2024-32228

    Last Modified: 3 Jun 2025

    FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a SEGV at libavcodec/hevcdec.c:2947:22 in hevc_frame_end.

    Published: 1 Jul 2024
    7.8
    High

    CVE-2024-32230

    Last Modified: 14 Mar 2025

    FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a negative-size-param bug at libavcodec/mpegvideo_enc.c:1216:21 in load_input_picture in FFmpeg7.0

    Published: 1 Jul 2024
    7.5
    High

    CVE-2024-39573

    Last Modified: 3 Nov 2025

    Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by mod_proxy. Users are recommended to upgrade to version 2.4.60, which fixes this issue.

    Published: 1 Jul 2024
    5.4
    Medium

    CVE-2024-37763

    Last Modified: 30 Apr 2025

    MachForm up to version 19 is affected by an unauthenticated stored cross-site scripting which affects users with valid sessions whom can view compiled forms results.

    Published: 1 Jul 2024
    5.4
    Medium

    CVE-2024-37764

    Last Modified: 30 Apr 2025

    MachForm up to version 19 is affected by an authenticated stored cross-site scripting.

    Published: 1 Jul 2024
    8.8
    High

    CVE-2024-37765

    Last Modified: 30 Apr 2025

    Machform up to version 19 is affected by an authenticated Blind SQL injection in the user account settings page.

    Published: 1 Jul 2024
    7.5
    High

    CVE-2024-38472

    Last Modified: 1 Jul 2025

    SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users are recommended to upgrade to version 2.4.60 which fixes this issue.  Note: Existing configurations that access UNC paths will have to configure new directive "UNCList" to allow access during request processing.

    Published: 1 Jul 2024
    8.1
    High

    CVE-2024-38473

    Last Modified: 1 Jul 2025

    Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests. Users are recommended to upgrade to version 2.4.60, which fixes this issue.

    Published: 1 Jul 2024
    9.8
    Critical

    CVE-2024-38476

    Last Modified: 3 Nov 2025

    Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue.

    Published: 1 Jul 2024
    7.5
    High

    CVE-2024-38477

    Last Modified: 3 Nov 2025

    null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request. Users are recommended to upgrade to version 2.4.60, which fixes this issue.

    Published: 1 Jul 2024
    6.3
    Medium

    CVE-2024-38990

    Last Modified: 15 Apr 2026

    Tada5hi sp-common v0.5.4 was discovered to contain a prototype pollution via the function mergeDeep. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

    Published: 1 Jul 2024
    8.8
    High

    CVE-2024-38991

    Last Modified: 15 Apr 2026

    akbr patch-into v1.0.1 was discovered to contain a prototype pollution via the function patchInto. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

    Published: 1 Jul 2024
    8.8
    High

    CVE-2024-38992

    Last Modified: 15 Apr 2026

    airvertco frappejs v0.0.11 was discovered to contain a prototype pollution via the function registerView. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

    Published: 1 Jul 2024
    9.8
    Critical

    CVE-2024-38993

    Last Modified: 10 Jul 2025

    rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function empty. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

    Published: 1 Jul 2024
    7.3
    High

    CVE-2024-38994

    Last Modified: 7 Jul 2025

    amoyjs amoy common v1.0.10 was discovered to contain a prototype pollution via the function extend. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

    Published: 1 Jul 2024
    9.8
    Critical

    CVE-2024-38996

    Last Modified: 28 Apr 2025

    ag-grid-community v31.3.2 and ag-grid-enterprise v31.3.2 were discovered to contain a prototype pollution via the _.mergeDeep function. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

    Published: 1 Jul 2024
    6.5
    Medium

    CVE-2024-38998

    Last Modified: 28 Jan 2025

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 1 Jul 2024
    10
    Critical

    CVE-2024-38999

    Last Modified: 15 Apr 2026

    jrburke requirejs v2.3.6 was discovered to contain a prototype pollution via the function s.contexts._.configure. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

    Published: 1 Jul 2024
    6.5
    Medium

    CVE-2024-39000

    Last Modified: 7 Jul 2025

    adolph_dudu ratio-swiper v0.0.2 was discovered to contain a prototype pollution via the function parse. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

    Published: 1 Jul 2024
    6.3
    Medium

    CVE-2024-39002

    Last Modified: 7 Jul 2025

    rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function util.clone. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

    Published: 1 Jul 2024
    8.1
    High

    CVE-2024-39016

    Last Modified: 15 Apr 2026

    che3vinci c3/utils-1 1.0.131 was discovered to contain a prototype pollution via the function assign. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

    Published: 1 Jul 2024
    6.3
    Medium

    CVE-2024-39018

    Last Modified: 15 Apr 2026

    harvey-woo cat5th/key-serializer v0.2.5 was discovered to contain a prototype pollution via the function "query". This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

    Published: 1 Jul 2024
    9.8
    Critical

    CVE-2024-39236

    Last Modified: 27 Jun 2025

    Gradio v4.36.1 was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py. This vulnerability is triggered via a crafted input. NOTE: the supplier disputes this because the report is about a user attacking himself.

    Published: 1 Jul 2024
    5.3
    Medium

    CVE-2024-6419

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical was found in SourceCodester Medicine Tracker System 1.0. This vulnerability affects unknown code of the file /classes/Master.php?f=save_medicine. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-270010 is the identifier assigned to this vulnerability.

    Published: 30 Jun 2024
    6.9
    Medium

    CVE-2024-6418

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical has been found in SourceCodester Medicine Tracker System 1.0. This affects an unknown part of the file /classes/Users.php?f=register_user. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-270009 was assigned to this vulnerability.

    Published: 30 Jun 2024
    5.3
    Medium

    CVE-2024-6417

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/ajax.php?action=delete_user. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-270008.

    Published: 30 Jun 2024
    5.3
    Medium

    CVE-2024-6416

    Last Modified: 5 Apr 2025

    A vulnerability was found in SeaCMS 12.9. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /js/player/dmplayer/dmku/?ac=edit. The manipulation of the argument cid with the input (select(0)from(select(sleep(10)))v) leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-270007.

    Published: 30 Jun 2024
    7.5
    High

    CVE-2024-34703

    Last Modified: 15 Apr 2026

    Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the parameters. Prior to versions 3.3.0 and 2.19.4, an attacker could present an ECDSA X.509 certificate using explicit encoding where the parameters are very large. The proof of concept used a 16Kbit prime for this purpose. When parsing, the parameter is checked to be prime, causing excessive computation. This was patched in 2.19.4 and 3.3.0 to allow the prime parameter of the elliptic curve to be at most 521 bits. No known workarounds are available. Note that support for explicit encoding of elliptic curve parameters is deprecated in Botan.

    Published: 30 Jun 2024
    5.4
    Medium

    CVE-2023-50964

    Last Modified: 21 Nov 2024

    IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 276102.

    Published: 30 Jun 2024
    5.4
    Medium

    CVE-2024-28794

    Last Modified: 21 Nov 2024

    IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 286831.

    Published: 30 Jun 2024
    5.4
    Medium

    CVE-2023-50953

    Last Modified: 21 Nov 2024

    IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system. IBM X-Force ID: 275775.

    Published: 30 Jun 2024
    5.4
    Medium

    CVE-2023-50952

    Last Modified: 21 Nov 2024

    IBM InfoSphere Information Server 11.7 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 275774.

    Published: 30 Jun 2024