Количество 26 125
Количество 26 125
CVE-2024-3154
Cri-o: arbitrary command injection via pod annotation
CVE-2024-31449
Lua library commands may lead to stack overflow and RCE in Redis
CVE-2024-31228
Denial-of-service due to unbounded pattern matching in Redis
CVE-2024-31227
Denial-of-service due to malformed ACL selectors in Redis
CVE-2024-31083
CVE-2024-31082
CVE-2024-31081
CVE-2024-31080
CVE-2024-3096
PHP function password_verify can erroneously return true when argument contains NUL
CVE-2024-30896
InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with read access to the authorization resource of the default organization to retrieve the operator token. InfluxDB OSS 1.x, Enterprise, Cloud, Cloud Dedicated and Clustered are not affected. NOTE: The researcher states that InfluxDB allows allAccess administrators to retrieve all raw tokens via an "influx auth ls" command. The supplier indicates that the organizations feature is operating as intended and that users may choose to add users to non-default organizations. A future release of InfluxDB 2.x will remove the ability to retrieve tokens from the API.
CVE-2024-30261
CVE-2024-30260
CVE-2024-30251
Denial of service when trying to parse malformed POST requests in aiohttp
CVE-2024-30205
In Emacs before 29.3 Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.
CVE-2024-30204
In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.
CVE-2024-30203
CVE-2024-30202
CVE-2024-30166
CVE-2024-30161
In Qt 6.5.4, 6.5.5, and 6.6.2, QNetworkReply header data might be accessed via a dangling pointer in Qt for WebAssembly (wasm). (Earlier and later versions are unaffected.)
CVE-2024-30105
.NET and Visual Studio Denial of Service Vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-3154 Cri-o: arbitrary command injection via pod annotation | CVSS3: 7.2 | 1% Низкий | около 2 лет назад | |
CVE-2024-31449 Lua library commands may lead to stack overflow and RCE in Redis | CVSS3: 7 | 4% Низкий | больше 1 года назад | |
CVE-2024-31228 Denial-of-service due to unbounded pattern matching in Redis | CVSS3: 5.5 | 1% Низкий | почти 2 года назад | |
CVE-2024-31227 Denial-of-service due to malformed ACL selectors in Redis | CVSS3: 4.4 | 0% Низкий | почти 2 года назад | |
CVSS3: 7.8 | 2% Низкий | около 2 лет назад | ||
CVSS3: 7.3 | 0% Низкий | около 2 лет назад | ||
CVSS3: 7.3 | 1% Низкий | около 2 лет назад | ||
CVSS3: 7.3 | 1% Низкий | почти 2 года назад | ||
CVE-2024-3096 PHP function password_verify can erroneously return true when argument contains NUL | CVSS3: 6.5 | 1% Низкий | 6 месяцев назад | |
CVE-2024-30896 InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with read access to the authorization resource of the default organization to retrieve the operator token. InfluxDB OSS 1.x, Enterprise, Cloud, Cloud Dedicated and Clustered are not affected. NOTE: The researcher states that InfluxDB allows allAccess administrators to retrieve all raw tokens via an "influx auth ls" command. The supplier indicates that the organizations feature is operating as intended and that users may choose to add users to non-default organizations. A future release of InfluxDB 2.x will remove the ability to retrieve tokens from the API. | 5% Низкий | 7 месяцев назад | ||
CVSS3: 3.5 | 1% Низкий | больше 2 лет назад | ||
CVSS3: 4.3 | 1% Низкий | больше 1 года назад | ||
CVE-2024-30251 Denial of service when trying to parse malformed POST requests in aiohttp | 1% Низкий | 12 месяцев назад | ||
CVE-2024-30205 In Emacs before 29.3 Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23. | CVSS3: 7.1 | 0% Низкий | около 2 лет назад | |
CVE-2024-30204 In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments. | CVSS3: 2.8 | 0% Низкий | 12 месяцев назад | |
CVSS3: 5.5 | 1% Низкий | почти 2 года назад | ||
CVSS3: 7.8 | 1% Низкий | почти 2 года назад | ||
CVSS3: 9.1 | 1% Низкий | больше 1 года назад | ||
CVE-2024-30161 In Qt 6.5.4, 6.5.5, and 6.6.2, QNetworkReply header data might be accessed via a dangling pointer in Qt for WebAssembly (wasm). (Earlier and later versions are unaffected.) | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
CVE-2024-30105 .NET and Visual Studio Denial of Service Vulnerability | CVSS3: 7.5 | 3% Низкий | около 2 лет назад |
Уязвимостей на страницу