5.4

CVSS3.1

CVE-2024-56364 - Cross-site Scripting vulnerability in SimpleXLSXEx::readThemeColors, SimpleXLSXEx::getColorValue an…

SimpleXLSX is software for parsing and retrieving data from Excel XLSx files. Starting in 1.0.12 and ending in 1.1.13, when calling the extended toHTMLEx method, it is possible to execute arbitrary JavaScript code. This vulnerability is fixed in 1.1.13.

πŸ“… Published: Dec. 23, 2024, 3:52 p.m. πŸ”„ Last Modified: Dec. 28, 2024, 12:48 a.m.

5.4

CVSS4.0

CVE-2024-56326 - Jinja has a sandbox breakout through indirect reference to format method

Jinja is an extensible templating engine. Prior to 3.1.5, An oversight in how the Jinja sandboxed environment detects calls to str.format allows an attacker that controls the content of a template to execute arbitrary Python code. To exploit the vulnerability, an attacker needs to control the conte…

πŸ“… Published: Dec. 23, 2024, 3:43 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 8:16 p.m.

5.4

CVSS4.0

CVE-2024-56201 - Jinja has a sandbox breakout through malicious filenames

Jinja is an extensible templating engine. In versions on the 3.x branch prior to 3.1.5, a bug in the Jinja compiler allows an attacker that controls both the content and filename of a template to execute arbitrary Python code, regardless of if Jinja's sandbox is used. To exploit the vulnerability, …

πŸ“… Published: Dec. 23, 2024, 3:37 p.m. πŸ”„ Last Modified: Sept. 22, 2025, 5:45 p.m.

9.9

CVSS3.1

CVE-2024-45387 - Apache Traffic Control: SQL Injection in Traffic Ops endpoint PUT deliveryservice_request_comments

An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", "operations", "portal", or "steering" to execute arbitrary SQL against the database by sending a specially-crafted PUT request. Users are recommended…

πŸ“… Published: Dec. 23, 2024, 3:30 p.m. πŸ”„ Last Modified: Feb. 11, 2025, 4:07 p.m.

5.9

CVSS3.1

CVE-2024-23945 - Apache Hive, Apache Spark, Apache Spark: CookieSigner exposes the correct signature when message ve…

Signing cookies is an application security feature that adds a digital signature to cookie data to verify its authenticity and integrity. The signature helps prevent malicious actors from modifying the cookie value, which can lead to security vulnerabilities and exploitation. Apache Hive’s service …

πŸ“… Published: Dec. 23, 2024, 3:26 p.m. πŸ”„ Last Modified: July 14, 2025, 6:32 p.m.

8.7

CVSS4.0

CVE-2024-55947 - Gogs has a Path Traversal in file update API

Gogs is an open source self-hosted Git service. A malicious user is able to write a file to an arbitrary path on the server to gain SSH access to the server. The vulnerability is fixed in 0.13.1.

πŸ“… Published: Dec. 23, 2024, 3:26 p.m. πŸ”„ Last Modified: April 10, 2025, 2:47 p.m.

8.7

CVSS4.0

CVE-2024-54148 - Gogs has a Path Traversal in file editing UI

Gogs is an open source self-hosted Git service. A malicious user is able to commit and edit a crafted symlink file to a repository to gain SSH access to the server. The vulnerability is fixed in 0.13.1.

πŸ“… Published: Dec. 23, 2024, 3:22 p.m. πŸ”„ Last Modified: April 10, 2025, 2:48 p.m.

7.8

CVSS3.1

CVE-2024-53256 - Rizin has a command injection via RzBinInfo bclass due legacy code

Rizin is a UNIX-like reverse engineering framework and command-line toolset. `rizin.c` still had an old snippet of code which suffered a command injection due the usage of `rz_core_cmdf` to invoke the command `m` which was removed in v0.1.x. A malicious binary defining `bclass` (part of RzBinInfo) …

πŸ“… Published: Dec. 23, 2024, 3:17 p.m. πŸ”„ Last Modified: Dec. 24, 2024, 1:55 a.m.

2.5

CVSS3.0

CVE-2024-55539 -

Weak algorithm used to sign RPM package. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux) before build 39185, Acronis Cyber Protect 16 (Linux) before build 39938.

πŸ“… Published: Dec. 23, 2024, 2:05 p.m. πŸ”„ Last Modified: June 4, 2025, 2:15 p.m.

7.8

CVSS3.1

CVE-2024-12903 - Incorrect default permissions in Biamp Evoko Home

Incorrect default permissions vulnerability in Evoko Home, affecting version 2.4.2 to 2.7.4. A non-admin user could exploit weak file and folder permissions to escalate privileges, execute arbitrary code and maintain persistence on the compromised machine. It has been identified that full control p…

πŸ“… Published: Dec. 23, 2024, 12:41 p.m. πŸ”„ Last Modified: Dec. 24, 2024, 1:59 a.m.
Total resulsts: 343921
Page 6865 of 34,393
Β« previous page Β» next page
Filters