Latest CVE Feed
-
5.3
MEDIUMCVE-2024-56473
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 could allow an attacker to spoof their IP address, which is written to log files, due to improper verification of 'Client-IP' headers.... Read more
Affected Products : aspera_shares- Published: Feb. 05, 2025
- Modified: Mar. 06, 2025
- Vuln Type: Misconfiguration
-
6.4
MEDIUMCVE-2024-56472
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to creden... Read more
Affected Products : aspera_shares- Published: Feb. 05, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-56471
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attac... Read more
Affected Products : aspera_shares- Published: Feb. 05, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Server-Side Request Forgery
-
5.4
MEDIUMCVE-2024-56470
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attac... Read more
Affected Products : aspera_shares- Published: Feb. 05, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Server-Side Request Forgery
-
6.1
MEDIUMCVE-2024-38318
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.... Read more
Affected Products : aspera_shares- Published: Feb. 05, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-38317
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials dis... Read more
Affected Products : aspera_shares- Published: Feb. 05, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2024-38316
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service.... Read more
Affected Products : aspera_shares- Published: Feb. 05, 2025
- Modified: Mar. 06, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2024-57699
A security issue was found in Netplex Json-smart 2.5.0 through 2.5.1. When loading a specially crafted JSON input, containing a large number of ’{’, a stack exhaustion can be trigger, which could allow an attacker to cause a Denial of Service (DoS). This ... Read more
Affected Products :- Published: Feb. 05, 2025
- Modified: Feb. 06, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2024-57598
A floating point exception (divide-by-zero) vulnerability was discovered in Bento4 1.6.0-641 in function AP4_TfraAtom() of Ap4TfraAtom.cpp which allows a remote attacker to cause a denial of service vulnerability.... Read more
Affected Products : bento4- Published: Feb. 05, 2025
- Modified: May. 15, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2024-57520
Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function... Read more
Affected Products :- Published: Feb. 05, 2025
- Modified: Feb. 06, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2024-57086
A prototype pollution in the function fieldsToJson of node-opcua-alarm-condition v2.134.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.... Read more
Affected Products :- Published: Feb. 05, 2025
- Modified: Feb. 06, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2024-57085
A prototype pollution in the function deepMerge of @stryker-mutator/util v8.6.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.... Read more
Affected Products :- Published: Feb. 05, 2025
- Modified: Mar. 13, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2024-57084
A prototype pollution in the function lib.parse of dot-properties v1.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.... Read more
Affected Products :- Published: Feb. 05, 2025
- Modified: Feb. 07, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2024-57082
A prototype pollution in the lib.createUploader function of @rpldy/uploader v1.8.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.... Read more
Affected Products :- Published: Feb. 05, 2025
- Modified: Feb. 18, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2024-57081
A prototype pollution in the lib.fromQuery function of underscore-contrib v0.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.... Read more
Affected Products :- Published: Feb. 05, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2024-57080
A prototype pollution in the lib.install function of vxe-table v4.8.10 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.... Read more
Affected Products :- Published: Feb. 05, 2025
- Modified: Feb. 06, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2024-57079
A prototype pollution in the lib.deepMerge function of @zag-js/core v0.50.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.... Read more
Affected Products :- Published: Feb. 05, 2025
- Modified: Mar. 18, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2024-57078
A prototype pollution in the lib.merge function of cli-util v1.1.27 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.... Read more
Affected Products :- Published: Feb. 05, 2025
- Modified: Feb. 06, 2025
- Vuln Type: Denial of Service
-
9.1
CRITICALCVE-2024-57077
The latest version of utils-extend (1.0.8) is vulnerable to Prototype Pollution through the entry function(s) lib.extend. An attacker can supply a payload with Object.prototype setter to introduce or modify properties within the global prototype chain, ca... Read more
Affected Products : utils-extend- Published: Feb. 05, 2025
- Modified: Mar. 24, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2024-57076
A prototype pollution in the lib.post function of ajax-request v1.2.3 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.... Read more
Affected Products :- Published: Feb. 05, 2025
- Modified: Mar. 18, 2025
- Vuln Type: Denial of Service