Vulnerabilities (CVE)

Total 398493 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-21501 2 Apostrophecms, Fedoraproject 2 Sanitize-html, Fedora 2026-06-17 N/A 5.3 MEDIUM
Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including project dependencies). An attacker could exploit this vulnerability to gather details about the file system structure and dependencies of the targeted server.
CVE-2024-21500 1 Authcrunch 1 Caddy-security 2026-06-17 N/A 4.8 MEDIUM
All versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Restriction of Excessive Authentication Attempts via the two-factor authentication (2FA). Although the application blocks the user after several failed attempts to provide 2FA codes, attackers can bypass this blocking mechanism by automating the application’s full multistep 2FA process.
CVE-2024-21499 1 Greenpau 1 Caddy-security 2026-06-17 N/A 4.3 MEDIUM
All versions of the package github.com/greenpau/caddy-security are vulnerable to HTTP Header Injection via the X-Forwarded-Proto header due to redirecting to the injected protocol.Exploiting this vulnerability could lead to bypass of security mechanisms or confusion in handling TLS.
CVE-2024-21498 1 Authcrunch 1 Caddy-security 2026-06-17 N/A 5.3 MEDIUM
All versions of the package github.com/greenpau/caddy-security are vulnerable to Server-side Request Forgery (SSRF) via X-Forwarded-Host header manipulation. An attacker can expose sensitive information, interact with internal services, or exploit other vulnerabilities within the network by exploiting this vulnerability.
CVE-2024-21497 1 Greenpau 1 Caddy-security 2026-06-17 N/A 5.4 MEDIUM
Versions of the package github.com/greenpau/caddy-security are vulnerable to Open Redirect via the redirect_url parameter. An attacker could perform a phishing attack and trick users into visiting a malicious website by crafting a convincing URL with this parameter. To exploit this vulnerability, the user must take an action, such as clicking on a portal button or using the browser’s back button, to trigger the redirection.
CVE-2024-21496 1 Authcrunch 1 Caddy-security 2026-06-17 N/A 6.1 MEDIUM
All versions of the package github.com/greenpau/caddy-security are vulnerable to Cross-site Scripting (XSS) via the Referer header, due to improper input sanitization. Although the Referer header is sanitized by escaping some characters that can allow XSS (e.g., [&], [<], [>], ["], [']), it does not account for the attack based on the JavaScript URL scheme (e.g., javascript:alert(document.domain)// payload). Exploiting this vulnerability may not be trivial, but it could lead to the execution of malicious scripts in the context of the target user’s browser, compromising user sessions.
CVE-2024-21495 1 Greenpau 1 Caddy-security 2026-06-17 N/A 6.5 MEDIUM
Versions of the package github.com/greenpau/caddy-security before 1.0.42 are vulnerable to Insecure Randomness due to using an insecure random number generation library which could possibly be predicted via a brute-force search. Attackers could use the potentially predictable nonce value used for authentication purposes in the OAuth flow to conduct OAuth replay attacks. In addition, insecure randomness is used while generating multifactor authentication (MFA) secrets and creating API keys in the database package.
CVE-2024-21494 1 Greenpau 1 Caddy-security 2026-06-17 N/A 5.4 MEDIUM
All versions of the package github.com/greenpau/caddy-security are vulnerable to Authentication Bypass by Spoofing via the X-Forwarded-For header due to improper input sanitization. An attacker can spoof an IP address used in the user identity module (/whoami API endpoint). This could lead to unauthorized access if the system trusts this spoofed IP address.
CVE-2024-21493 1 Greenpau 1 Caddy-security 2026-06-17 N/A 5.3 MEDIUM
All versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Validation of Array Index when parsing a Caddyfile. Multiple parsing functions in the affected library do not validate whether their input values are nil before attempting to access elements, which can lead to a panic (index out of range). Panics during the parsing of a configuration file may introduce ambiguity and vulnerabilities, hindering the correct interpretation and configuration of the web server.
CVE-2024-21492 1 Authcrunch 1 Caddy-security 2026-06-17 N/A 4.8 MEDIUM
All versions of the package github.com/greenpau/caddy-security are vulnerable to Insufficient Session Expiration due to improper user session invalidation upon clicking the "Sign Out" button. User sessions remain valid even after requests are sent to /logout and /oauth2/google/logout. Attackers who gain access to an active but supposedly logged-out session can perform unauthorized actions on behalf of the user.
CVE-2024-21491 1 Svix 1 Svix-webhooks 2026-06-17 N/A 5.9 MEDIUM
Versions of the package svix before 1.17.0 are vulnerable to Authentication Bypass due to an issue in the verify function where signatures of different lengths are incorrectly compared. An attacker can bypass signature verification by providing a shorter signature that matches the beginning of the actual signature. **Note:** The attacker would need to know a victim uses the Rust library for verification,no easy way to automatically check that; and uses webhooks by a service that uses Svix, and then figure out a way to craft a malicious payload that will actually include all of the correct identifiers needed to trick the receivers to cause actual issues.
CVE-2024-21485 1 Plotly 1 Dash 2026-06-17 N/A 6.5 MEDIUM
Versions of the package dash-core-components before 2.13.0; versions of the package dash-core-components before 2.0.0; versions of the package dash before 2.15.0; versions of the package dash-html-components before 2.0.0; versions of the package dash-html-components before 2.0.16 are vulnerable to Cross-site Scripting (XSS) when the href of the a tag is controlled by an adversary. An authenticated attacker who stores a view that exploits this vulnerability could steal the data that's visible to another user who opens that view - not just the data already included on the page, but they could also, in theory, make additional requests and access other data accessible to this user. In some cases, they could also steal the access tokens of that user, which would allow the attacker to act as that user, including viewing other apps and resources hosted on the same server. **Note:** This is only exploitable in Dash apps that include some mechanism to store user input to be reloaded by a different user.
CVE-2024-21483 2026-06-17 N/A 4.6 MEDIUM
A vulnerability has been identified in SENTRON 7KM PAC3120 AC/DC (7KM3120-0BA01-1DA0) (All versions >= V3.2.3 < V3.2.4 only when manufactured between LQN231003... and LQN231215... ( with LQNYYMMDD...)), SENTRON 7KM PAC3120 DC (7KM3120-1BA01-1EA0) (All versions >= V3.2.3 < V3.2.4 only when manufactured between LQN231003... and LQN231215... ( with LQNYYMMDD...)), SENTRON 7KM PAC3220 AC/DC (7KM3220-0BA01-1DA0) (All versions >= V3.2.3 < V3.2.4 only when manufactured between LQN231003... and LQN231215... ( with LQNYYMMDD...)), SENTRON 7KM PAC3220 DC (7KM3220-1BA01-1EA0) (All versions >= V3.2.3 < V3.2.4 only when manufactured between LQN231003... and LQN231215... ( with LQNYYMMDD...)). The read out protection of the internal flash of affected devices was not properly set at the end of the manufacturing process. An attacker with physical access to the device could read out the data.
CVE-2024-21482 1 Qualcomm 138 Csr8811, Csr8811 Firmware, Immersive Home 214 Platform and 135 more 2026-06-17 N/A 6.8 MEDIUM
Memory corruption during the secure boot process, when the `bootm` command is used, it bypasses the authentication of the kernel/rootfs image.
CVE-2024-21481 1 Qualcomm 332 Aqt1000, Aqt1000 Firmware, Ar8035 and 329 more 2026-06-17 N/A 8.4 HIGH
Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager.
CVE-2024-21480 1 Qualcomm 230 Ar8035, Ar8035 Firmware, Fastconnect 6200 and 227 more 2026-06-17 N/A 7.3 HIGH
Memory corruption while playing audio file having large-sized input buffer.
CVE-2024-21479 1 Qualcomm 190 Ar8035, Ar8035 Firmware, Fastconnect 6700 and 187 more 2026-06-17 N/A 7.5 HIGH
Transient DOS during music playback of ALAC content.
CVE-2024-21478 1 Qualcomm 24 Qam8255p, Qam8255p Firmware, Qam8650p and 21 more 2026-06-17 N/A 6.2 MEDIUM
transient DOS when setting up a fence callback to free a KGSL memory entry object during DMA.
CVE-2024-21477 1 Qualcomm 368 Aqt1000, Aqt1000 Firmware, Ar8035 and 365 more 2026-06-17 N/A 7.5 HIGH
Transient DOS while parsing a protected 802.11az Fine Time Measurement (FTM) frame.
CVE-2024-21476 1 Qualcomm 96 Aqt1000, Aqt1000 Firmware, Ar8035 and 93 more 2026-06-17 N/A 7.8 HIGH
Memory corruption when the channel ID passed by user is not validated and further used.