Total
258583 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-34205 | 2024-07-03 | N/A | 7.3 HIGH | ||
| TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the download_firmware function. | |||||
| CVE-2024-34203 | 2024-07-03 | N/A | 3.8 LOW | ||
| TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setLanguageCfg function. | |||||
| CVE-2024-34202 | 2024-07-03 | N/A | 6.5 MEDIUM | ||
| TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setMacFilterRules function. | |||||
| CVE-2024-34201 | 2024-07-03 | N/A | 7.3 HIGH | ||
| TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the getSaveConfig function. | |||||
| CVE-2024-34200 | 2024-07-03 | N/A | 8.8 HIGH | ||
| TOTOLINK CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setIpQosRules function. | |||||
| CVE-2024-34199 | 2024-07-03 | N/A | 8.6 HIGH | ||
| TinyWeb 1.94 and below allows unauthenticated remote attackers to cause a denial of service (Buffer Overflow) when sending excessively large elements in the request line. | |||||
| CVE-2024-34148 | 2024-07-03 | N/A | 6.8 MEDIUM | ||
| Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier programmatically disables the fix for CVE-2016-3721 whenever a build is triggered from a release tag, by setting the Java system property 'hudson.model.ParametersAction.keepUndefinedParameters'. | |||||
| CVE-2024-34147 | 2024-07-03 | N/A | 4.3 MEDIUM | ||
| Jenkins Telegram Bot Plugin 1.4.0 and earlier stores the Telegram Bot token unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system. | |||||
| CVE-2024-34146 | 2024-07-03 | N/A | 6.5 MEDIUM | ||
| Jenkins Git server Plugin 114.v068a_c7cc2574 and earlier does not perform a permission check for read access to a Git repository over SSH, allowing attackers with a previously configured SSH public key but lacking Overall/Read permission to access these repositories. | |||||
| CVE-2024-34145 | 2024-07-03 | N/A | 8.8 HIGH | ||
| A sandbox bypass vulnerability involving sandbox-defined classes that shadow specific non-sandbox-defined classes in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM. | |||||
| CVE-2024-34144 | 2024-07-03 | N/A | 9.8 CRITICAL | ||
| A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM. | |||||
| CVE-2024-34093 | 2024-07-03 | N/A | 5.3 MEDIUM | ||
| An issue was discovered in Archer Platform 6 before 2024.03. There is an X-Forwarded-For Header Bypass vulnerability. An unauthenticated attacker could potentially bypass intended whitelisting when X-Forwarded-For header is enabled. | |||||
| CVE-2024-34091 | 2024-07-03 | N/A | 7.3 HIGH | ||
| An issue was discovered in Archer Platform 6 before 2024.04. There is a stored cross-site scripting (XSS) vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the data store through their browsers, the malicious code gets executed in the background of the application and renders content inaccessible. 6.14 P3 (6.14.0.3) is also a fixed release. | |||||
| CVE-2024-34058 | 2024-07-03 | N/A | 8.8 HIGH | ||
| The WebTop package for NethServer 7 and 8 allows stored XSS (for example, via the Subject field if an e-mail message). | |||||
| CVE-2024-34045 | 2024-07-03 | N/A | 7.5 HIGH | ||
| The O-RAN E2T I-Release Prometheus metric Increment function can crash in sctpThread.cpp for message.peerInfo->counters[IN_INITI][MSG_COUNTER][ProcedureCode_id_E2setup]->Increment(). | |||||
| CVE-2024-34030 | 2024-07-03 | N/A | N/A | ||
| In the Linux kernel, the following vulnerability has been resolved: PCI: of_property: Return error for int_map allocation failure Return -ENOMEM from of_pci_prop_intr_map() if kcalloc() fails to prevent a NULL pointer dereference in this case. [bhelgaas: commit log] | |||||
| CVE-2024-34020 | 2024-07-03 | N/A | 6.5 MEDIUM | ||
| A stack-based buffer overflow was found in the putSDN() function of mail.c in hcode through 2.1. | |||||
| CVE-2024-34006 | 2024-07-03 | N/A | 4.3 MEDIUM | ||
| The site log report required additional encoding of event descriptions to ensure any HTML in the content is displayed in plaintext instead of being rendered. | |||||
| CVE-2024-34003 | 2024-07-03 | N/A | 5.9 MEDIUM | ||
| In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore workshop modules and direct access to the web server outside of the Moodle webroot could execute a local file include. | |||||
| CVE-2024-34001 | 2024-07-03 | N/A | 8.4 HIGH | ||
| Actions in the admin preset tool did not include the necessary token to prevent a CSRF risk. | |||||
