CVE-2024-38533 : MATTER-LABS ERA-COMPILER-VYPER UP TO 1.4.X OUT-OF-BOUNDS WRITE

Description

ZKsync Era is a layer 2 rollup that uses zero-knowledge proofs to scale Ethereum. There is possible invalid stack access due to the addresses used to access the stack not properly being converted to cells. This issue has been patched in version 1.5.0.

References

https://github.com/matter-labs/era-compiler-vyper/security/advisories/GHSA-q7pg-6jh9-87gv

For More Information

CVERecord

Common Vulnerabilityies and Exposures

Contact us to get started

CVE-2024-5711 : STITIONAI DEVIKA CROSS SITE SCRIPTING

CVE-2024-5711 : STITIONAI DEVIKA CROSS SITE SCRIPTING

Description Cross-site Scripting (XSS) – Stored in GitHub repository stitionai/devika prior to -. References https://huntr.com/bounties/6c00ff84-574b-4b4f-bd58-aa7ec1809662 https://github.com/stitionai/devika/commit/6acce21fb08c3d1123ef05df6a33912bf0ee77c2 For More Information CVERecord

CVE-2024-38330 : IBM I 7.2/7.3/7.4 UNCONTROLLED SEARCH PATH

CVE-2024-38330 : IBM I 7.2/7.3/7.4 UNCONTROLLED SEARCH PATH

Description IBM System Management for i 7.2, 7.3, and 7.4 could allow a local user to gain elevated privileges due

CVE-2024-6539 : HEYEWEI SPRINGBOOTCMS UP TO 2024-05-28 GUESTBOOK /GUESTBOOK CONTENT CROSS SITE SCRIPTING

CVE-2024-6539 : HEYEWEI SPRINGBOOTCMS UP TO 2024-05-28 GUESTBOOK /GUESTBOOK CONTENT CROSS SITE SCRIPTING

Description A vulnerability classified as problematic has been found in heyewei SpringBootCMS up to 2024-05-28. Affected is an unknown function