Latest CVE Feed
-
2.2
LOWCVE-2024-53861
pyjwt is a JSON Web Token implementation in Python. An incorrect string comparison is run for `iss` checking, resulting in `"acb"` being accepted for `"_abc_"`. This is a bug introduced in version 2.10.0: checking the "iss" claim changed from `isinstance(... Read more
Affected Products : pyjwt- Published: Nov. 29, 2024
- Modified: Dec. 02, 2024
-
7.1
HIGHCVE-2024-53848
check-jsonschema is a CLI and set of pre-commit hooks for jsonschema validation. The default cache strategy uses the basename of a remote schema as the name of the file in the cache, e.g. `https://example.org/schema.json` will be stored as `schema.json`. ... Read more
Affected Products :- Published: Nov. 29, 2024
- Modified: Nov. 29, 2024
-
6.9
MEDIUMCVE-2024-52810
@intlify/shared is a shared library for the intlify project. The latest version of @intlify/shared (10.0.4) is vulnerable to Prototype Pollution through the entry function(s) lib.deepCopy. An attacker can supply a payload with Object.prototype setter to i... Read more
Affected Products :- Published: Nov. 29, 2024
- Modified: Nov. 29, 2024
-
5.3
MEDIUMCVE-2024-52809
vue-i18n is an internationalization plugin for Vue.js. In affected versions vue-i18n can be passed locale messages to `createI18n` or `useI18n`. When locale message ASTs are generated in development mode there is a possibility of Cross-site Scripting att... Read more
Affected Products :- Published: Nov. 29, 2024
- Modified: Nov. 29, 2024
-
5.3
MEDIUMCVE-2024-52801
sftpgo is a full-featured and highly configurable event-driven file transfer solution. Server protocols: SFTP, HTTP/S, FTP/S, WebDAV. The OpenID Connect implementation allows authenticated users to brute force session cookies and thereby gain access to ot... Read more
Affected Products : sftpgo- Published: Nov. 29, 2024
- Modified: Nov. 29, 2024
-
2.3
LOWCVE-2024-52800
veraPDF is an open source PDF/A validation library. Executing policy checks using custom schematron files via the CLI invokes an XSL transformation that may theoretically lead to a remote code execution (RCE) vulnerability. This doesn't affect the standar... Read more
Affected Products :- Published: Nov. 29, 2024
- Modified: Nov. 29, 2024
-
6.3
MEDIUMCVE-2024-52003
Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. There is a vulnerability in Traefik that allows the client to provide the X-Forwarded-Prefix header from an untrusted source. This issue has been addressed in versions 2.11.14 and 3.... Read more
Affected Products : traefik- Published: Nov. 29, 2024
- Modified: Nov. 29, 2024
-
6.5
MEDIUMCVE-2024-36616
An integer overflow in the component /libavformat/westwood_vqa.c of FFmpeg n6.1.1 allows attackers to cause a denial of service in the application via a crafted VQA file.... Read more
Affected Products : ffmpeg- Published: Nov. 29, 2024
- Modified: Jun. 03, 2025
-
5.9
MEDIUMCVE-2024-36615
FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while being read in the output thread.... Read more
Affected Products : ffmpeg- Published: Nov. 29, 2024
- Modified: Jun. 03, 2025
-
7.5
HIGHCVE-2024-36611
In Symfony v7.07, a security vulnerability was identified in the FormLoginAuthenticator component, where it failed to adequately handle cases where the username or password field of a login request is empty. This flaw could lead to various security risks,... Read more
Affected Products : symfony- Published: Nov. 29, 2024
- Modified: Dec. 03, 2024
-
9.2
CRITICALCVE-2024-49360
Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. An authenticated user (**UserA**) with no privileges is authorized to read all files created in sandbox belonging to other users in the sandbox folde... Read more
- Published: Nov. 29, 2024
- Modified: Aug. 04, 2025
-
5.4
MEDIUMCVE-2024-36624
Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the construct_copy_div function in copy_and_paste.js.... Read more
Affected Products :- Published: Nov. 29, 2024
- Modified: Nov. 29, 2024
-
8.1
HIGHCVE-2024-36623
moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data corruption or application crashes.... Read more
Affected Products : moby- Published: Nov. 29, 2024
- Modified: Jul. 02, 2025
-
9.8
CRITICALCVE-2024-36622
In RaspAP raspap-webgui 3.0.9 and earlier, a command injection vulnerability exists in the clearlog.php script. The vulnerability is due to improper sanitization of user input passed via the logfile parameter.... Read more
- Published: Nov. 29, 2024
- Modified: Jul. 02, 2025
-
6.5
MEDIUMCVE-2024-36621
moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function resulting in resource leaks/exhaustion.... Read more
Affected Products : moby- Published: Nov. 29, 2024
- Modified: Jul. 02, 2025
-
6.5
MEDIUMCVE-2024-36620
moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go.... Read more
Affected Products : moby- Published: Nov. 29, 2024
- Modified: Dec. 04, 2024
-
6.2
MEDIUMCVE-2024-36618
FFmpeg n6.1.1 has a vulnerability in the AVI demuxer of the libavformat library which allows for an integer overflow, potentially resulting in a denial-of-service (DoS) condition.... Read more
Affected Products : ffmpeg- Published: Nov. 29, 2024
- Modified: Jun. 03, 2025
-
6.2
MEDIUMCVE-2024-36617
FFmpeg n6.1.1 has an integer overflow vulnerability in the FFmpeg CAF decoder.... Read more
Affected Products : ffmpeg- Published: Nov. 29, 2024
- Modified: Jun. 03, 2025
-
9.8
CRITICALCVE-2024-49806
IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of intern... Read more
Affected Products : security_verify_access- Published: Nov. 29, 2024
- Modified: Jan. 29, 2025
-
9.8
CRITICALCVE-2024-49805
IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of intern... Read more
Affected Products : security_verify_access- Published: Nov. 29, 2024
- Modified: Jan. 29, 2025