CVE-2024-47554
- EPSS 0.21%
- Published 03.10.2024 12:15:02
- Last modified 10.07.2025 21:10:32
Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from...
CVE-2024-47561
- EPSS 1.59%
- Published 03.10.2024 11:15:13
- Last modified 10.07.2025 21:04:01
Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code. Users are recommended to upgrade to version 1.11.4 or 1.12.0, which fix this issue.
CVE-2024-7254
- EPSS 0.08%
- Published 19.09.2024 01:15:10
- Last modified 26.09.2025 17:10:19
Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. StackOverflow. Parsing nested groups as unknown fields with DiscardUnknown...
CVE-2024-8096
- EPSS 0.21%
- Published 11.09.2024 10:15:02
- Last modified 30.07.2025 19:42:16
When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly consider the response as fine. ...
CVE-2024-8372
- EPSS 0.17%
- Published 09.09.2024 15:15:12
- Last modified 28.04.2025 14:15:20
Improper sanitization of the value of the 'srcset' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This...
CVE-2024-8373
- EPSS 0.03%
- Published 09.09.2024 15:15:12
- Last modified 12.02.2025 20:15:05
Improper sanitization of the value of the [srcset] attribute in <source> HTML elements in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attack...
CVE-2024-6119
- EPSS 4.4%
- Published 03.09.2024 16:15:07
- Last modified 03.06.2025 10:51:54
Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal term...
CVE-2024-38808
- EPSS 0.27%
- Published 20.08.2024 08:15:05
- Last modified 18.06.2025 12:10:28
In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition. Specifically, an ap...
CVE-2024-21147
- EPSS 0.53%
- Published 16.07.2024 23:15:16
- Last modified 17.06.2025 19:57:24
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0...
CVE-2024-21140
- EPSS 0.42%
- Published 16.07.2024 23:15:15
- Last modified 18.06.2025 12:09:38
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0...