Updated at UTC 2024-05-04T12:14:25.689900

Access data as JSON


CVE CVSS Git URL Published Description
CVE-2024-34455 - https://github.com/buildroot/buildroot/commit/0b2967e15800421efbdfe3a7a6061cf6bd84134d 2024-05-03T19:15:07.950 Buildroot before 0b2967e lacks the sticky bit for the /dev/shm directory.
CVE-2024-34453 - https://github.com/tznb1/twonav/issues/9#issuecomment-2022194939 2024-05-03T18:15:10.160 TwoNav 2.1.13 contains an SSRF vulnerability via the url paramater to index.php?c=api&method=read_data&type=connectivity_test (which reaches /system/api.php).
CVE-2024-31673 - https://github.com/kliqqi-cms/kliqqi-cms/issues/265 2024-05-03T18:15:09.310 Kliqqi-CMS 2.0.2 is vulnerable to SQL Injection in load_data.php via the userid parameter.
CVE-2024-31636 - https://github.com/lief-project/lief/issues/1038 2024-05-03T17:15:07.687 An issue in LIEF v.0.14.1 allows a local attacker to obtain sensitive information via the name parameter of the machd_reader.c component.
CVE-2024-34449 - https://github.com/vanessa219/vditor/issues/1604 2024-05-03T16:15:11.520 Vditor 3.10.3 allows XSS via an attribute of an A element. NOTE: the vendor indicates that a user is supposed to mitigate this via sanitize=true.
CVE-2024-34063 2.5 https://github.com/matrix-org/vodozemac/commit/297548cad4016ce448c4b5007c54db7ee39489d9 2024-05-03T10:15:08.690 vodozemac is an implementation of Olm and Megolm in pure Rust. Versions 0.5.0 and 0.5.1 of vodozemac have degraded secret zeroization capabilities, due to changes in third-party cryptographic dependencies (the Dalek crates), which moved secret zeroization capabilities behind a feature flag and defaulted this feature to off. The degraded zeroization capabilities could result in the production of more memory copies of encryption secrets and secrets could linger in memory longer than necessary. This marginally increases the risk of sensitive data exposure. This issue has been addressed in version 0.6.0 and users are advised to upgrade. There are no known workarounds for this vulnerability.
CVE-2024-34408 - https://github.com/tencent/libpag/pull/2243 2024-05-03T06:15:13.883 Tencent libpag through 4.3.51 has an integer overflow in DecodeStream::checkEndOfFile() in codec/utils/DecodeStream.cpp via a crafted PAG (Portable Animated Graphics) file.
CVE-2024-34403 - https://github.com/uriparser/uriparser/pull/186 2024-05-03T01:15:48.693 An issue was discovered in uriparser through 0.9.7. ComposeQueryMallocExMm in UriQuery.c has an integer overflow via a long string.
CVE-2024-34402 - https://github.com/uriparser/uriparser/pull/185 2024-05-03T01:15:48.633 An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer overflow.
CVE-2024-4216 7.4 https://github.com/pgadmin-org/pgadmin4/issues/7282 2024-05-02T18:15:07.757 pgAdmin <= 8.5 is affected by XSS vulnerability in /settings/store API response json payload. This vulnerability allows attackers to execute malicious script at the client end.
CVE-2024-3955 - https://github.com/pibrewing/craftbeerpi4/issues/132 2024-05-02T10:15:08.630 URL GET parameter "logtime" utilized within the "downloadlog" function from "cbpi/http_endpoints/http_system.py" is subsequently passed to the "os.system" function in "cbpi/controller/system_controller.py" without prior validation allowing to execute arbitrary code.This issue affects CraftBeerPi 4: from 4.0.0.58 (commit 563fae9) before 4.4.1.a1 (commit 57572c7).
CVE-2024-33431 - https://github.com/stsaz/phiola/issues/27 2024-05-01T19:15:27.283 An issue in phiola/src/afilter/conv.c:115 of phiola v2.0-rc22 allows a remote attacker to cause a denial of service via a crafted .wav file.
CVE-2024-33430 - https://github.com/stsaz/phiola/issues/28 2024-05-01T19:15:27.223 An issue in phiola/src/afilter/pcm_convert.h:513 of phiola v2.0-rc22 allows a remote attacker to execute arbitrary code via the a crafted .wav file.
CVE-2024-33429 - https://github.com/stsaz/phiola/issues/30 2024-05-01T19:15:27.170 Buffer-Overflow vulnerability at pcm_convert.h:513 of phiola v2.0-rc22 allows a remote attacker to execute arbitrary code via a crafted .wav file.
CVE-2024-33428 - https://github.com/stsaz/phiola/issues/29 2024-05-01T19:15:27.120 Buffer-Overflow vulnerability at conv.c:68 of stsaz phiola v2.0-rc22 allows a remote attacker to execute arbitrary code via the a crafted .wav file.