6.5

CVSS3.1

CVE-2024-11946 - iXsystems TrueNAS CORE fetch_plugin_packagesites tar Cleartext Transmission of Sensitive Informatio…

iXsystems TrueNAS CORE fetch_plugin_packagesites tar Cleartext Transmission of Sensitive Information Vulnerability. This vulnerability allows network-adjacent attackers to tamper with firmware update files on affected installations of iXsystems TrueNAS devices. Authentication is not required to exp…

πŸ“… Published: Dec. 30, 2024, 8:12 p.m. πŸ”„ Last Modified: Aug. 18, 2025, 2:52 p.m.

8.8

CVSS3.1

CVE-2024-11944 - iXsystems TrueNAS CORE tarfile.extractall Directory Traversal Remote Code Execution Vulnerability

iXsystems TrueNAS CORE tarfile.extractall Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of iXsystems TrueNAS devices. Authentication is not required to exploit this vulnerability. Th…

πŸ“… Published: Dec. 30, 2024, 8:12 p.m. πŸ”„ Last Modified: Aug. 18, 2025, 2:55 p.m.

7.4

CVSS3.1

CVE-2024-56800 - Firecrawl has SSRF Vulnerability via malicious scrape target

Firecrawl is a web scraper that allows users to extract the content of a webpage for a large language model. Versions prior to 1.1.1 contain a server-side request forgery (SSRF) vulnerability. The scraping engine could be exploited by crafting a malicious site that redirects to a local IP address. …

πŸ“… Published: Dec. 30, 2024, 6:23 p.m. πŸ”„ Last Modified: Dec. 30, 2024, 11:13 p.m.

10

CVSS3.1

CVE-2024-56799 - Simofa Allows Unauthenticated Access to API Routes

Simofa is a tool to help automate static website building and deployment. Prior to version 0.2.7, due to a design mistake in the RouteLoader class, some API routes may be publicly accessible when they should require authentication. This vulnerability has been patched in v0.2.7.

πŸ“… Published: Dec. 30, 2024, 6:20 p.m. πŸ”„ Last Modified: Dec. 30, 2024, 11:14 p.m.

6.9

CVSS4.0

CVE-2024-56801 - Tasklists has Blind SQL Injection in /ajax/reorder.php

Tasklists provides plugin tasklists for GLPI. Versions prior to 2.0.4 have a blind SQL injection vulnerability. Version 2.0.4 contains a patch for the vulnerability.

πŸ“… Published: Dec. 30, 2024, 6:10 p.m. πŸ”„ Last Modified: Feb. 7, 2025, 3:24 p.m.

5.5

CVSS3.0

CVE-2024-12754 - AnyDesk Link Following Information Disclosure Vulnerability

AnyDesk Link Following Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulne…

πŸ“… Published: Dec. 30, 2024, 4:51 p.m. πŸ”„ Last Modified: Aug. 14, 2025, 6:46 p.m.

7.8

CVSS3.0

CVE-2024-12836 - Delta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution Vulnerability

Delta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics DRASimuCAD. User interaction is required to exploit this vulnerability in that the ta…

πŸ“… Published: Dec. 30, 2024, 4:50 p.m. πŸ”„ Last Modified: July 11, 2025, 6:20 p.m.

7.8

CVSS3.0

CVE-2024-12835 - Delta Electronics DRASimuCAD ICS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerabili…

Delta Electronics DRASimuCAD ICS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics DRASimuCAD. User interaction is required to exploit this vulnerability in that t…

πŸ“… Published: Dec. 30, 2024, 4:49 p.m. πŸ”„ Last Modified: July 11, 2025, 6:22 p.m.

7.8

CVSS3.0

CVE-2024-12834 - Delta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution Vulnerability

Delta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics DRASimuCAD. User interaction is required to exploit this vulnerability in that the ta…

πŸ“… Published: Dec. 30, 2024, 4:49 p.m. πŸ”„ Last Modified: July 11, 2025, 6:21 p.m.

7.9

CVSS4.0

CVE-2024-56734 - Better Auth has an Open Redirect Vulnerability in Verify Email Endpoint

Better Auth is an authentication library for TypeScript. An open redirect vulnerability has been identified in the verify email endpoint of all versions of Better Auth prior to v1.1.6, potentially allowing attackers to redirect users to malicious websites. This issue affects users relying on email …

πŸ“… Published: Dec. 30, 2024, 4:48 p.m. πŸ”„ Last Modified: Oct. 20, 2025, 4:15 p.m.
Total resulsts: 344009
Page 6812 of 34,401
Β« previous page Β» next page
Filters