CVE-2024-34069
- EPSS 38.93%
- Veröffentlicht 06.05.2024 15:15:23
- Zuletzt bearbeitet 03.12.2025 15:32:11
Werkzeug is a comprehensive WSGI web application library. The debugger in affected versions of Werkzeug can allow an attacker to execute code on a developer's machine under some circumstances. This requires the attacker to get the developer to intera...
CVE-2024-34500
- EPSS 0.3%
- Veröffentlicht 05.05.2024 19:15:07
- Zuletzt bearbeitet 04.11.2025 18:16:22
An issue was discovered in the UnlinkedWikibase extension in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. XSS can occur through an interface message. Error messages (in the $err var) are not escaped before being passed to ...
CVE-2024-34502
- EPSS 0.16%
- Veröffentlicht 05.05.2024 19:15:07
- Zuletzt bearbeitet 04.11.2025 18:16:22
An issue was discovered in WikibaseLexeme in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. Loading Special:MergeLexemes will (attempt to) make an edit that merges the from-id to the to-id, even if the request was not a POST...
CVE-2024-34506
- EPSS 0.17%
- Veröffentlicht 05.05.2024 19:15:07
- Zuletzt bearbeitet 04.11.2025 18:16:22
An issue was discovered in includes/specials/SpecialMovePage.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. If a user with the necessary rights to move the page opens Special:MovePage for a page with tens of thousands...
CVE-2024-34507
- EPSS 0.44%
- Veröffentlicht 05.05.2024 19:15:07
- Zuletzt bearbeitet 04.11.2025 18:16:22
An issue was discovered in includes/CommentFormatter/CommentParser.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. XSS can occur because of mishandling of the 0x1b character, as demonstrated by Special:RecentChanges#%1...
CVE-2024-34402
- EPSS 0.51%
- Veröffentlicht 03.05.2024 01:15:48
- Zuletzt bearbeitet 04.11.2025 18:16:21
An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer overflow.
CVE-2024-34403
- EPSS 0.48%
- Veröffentlicht 03.05.2024 01:15:48
- Zuletzt bearbeitet 04.11.2025 18:16:21
An issue was discovered in uriparser through 0.9.7. ComposeQueryMallocExMm in UriQuery.c has an integer overflow via a long string.
CVE-2024-4140
- EPSS 0.28%
- Veröffentlicht 02.05.2024 20:15:07
- Zuletzt bearbeitet 26.08.2025 17:21:28
An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1.954, which can cause denial of service when parsing multipart MIME messages. The patch set (from 2020 and 2024) limits excessive depth and the total number of parts.
CVE-2024-4215
- EPSS 0.03%
- Veröffentlicht 02.05.2024 18:15:07
- Zuletzt bearbeitet 19.09.2025 13:37:32
pgAdmin <= 8.5 is affected by a multi-factor authentication bypass vulnerability. This vulnerability allows an attacker with knowledge of a legitimate account’s username and password may authenticate to the application and perform sensitive actions w...
CVE-2024-4216
- EPSS 0.21%
- Veröffentlicht 02.05.2024 18:15:07
- Zuletzt bearbeitet 19.09.2025 13:27:28
pgAdmin <= 8.5 is affected by XSS vulnerability in /settings/store API response json payload. This vulnerability allows attackers to execute malicious script at the client end.