8.5

CVSS4.0

CVE-2024-12677 - Delta Electronics DTM Soft Deserialization of Untrusted Data

Delta Electronics DTM Soft deserializes objects, which could allow an attacker to execute arbitrary code.

๐Ÿ“… Published: Dec. 20, 2024, 4:44 p.m. ๐Ÿ”„ Last Modified: Dec. 24, 2024, 12:40 a.m.

8.6

CVSS4.0

CVE-2024-10385 - Stored XSS in DirectAdmin Evo Skin

Ticket management system in DirectAdmin Evolution Skin is vulnerable to XSS (Cross-site Scripting), which allows a low-privileged user to inject and store malicious JavaScript code. If an admin views the ticket, the script might perform actions with their privileges, including command execution.ย  Tโ€ฆ

๐Ÿ“… Published: Dec. 20, 2024, 3:52 p.m. ๐Ÿ”„ Last Modified: Dec. 20, 2024, 4:48 p.m.

9.8

CVSS3.1

CVE-2024-56337 - Apache Tomcat: RCE due to TOCTOU issue in JSP compilation - CVE-2024-50379 mitigation was incomplete

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. The following versions were EOL at the time the CVE was created but are known to be affeโ€ฆ

๐Ÿ“… Published: Dec. 20, 2024, 3:28 p.m. ๐Ÿ”„ Last Modified: Nov. 4, 2025, 3:59 p.m.

5.9

CVSS3.1

CVE-2024-56356 -

In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack

๐Ÿ“… Published: Dec. 20, 2024, 2:11 p.m. ๐Ÿ”„ Last Modified: Jan. 2, 2025, 6:46 p.m.

4.6

CVSS3.1

CVE-2024-56355 -

In JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController response could lead to XSS

๐Ÿ“… Published: Dec. 20, 2024, 2:11 p.m. ๐Ÿ”„ Last Modified: Jan. 2, 2025, 6:46 p.m.

5.5

CVSS3.1

CVE-2024-56354 -

In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission

๐Ÿ“… Published: Dec. 20, 2024, 2:11 p.m. ๐Ÿ”„ Last Modified: Jan. 2, 2025, 6:47 p.m.

5.5

CVSS3.1

CVE-2024-56353 -

In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies

๐Ÿ“… Published: Dec. 20, 2024, 2:11 p.m. ๐Ÿ”„ Last Modified: Jan. 2, 2025, 6:48 p.m.

4.6

CVSS3.1

CVE-2024-56352 -

In JetBrains TeamCity before 2024.12 stored XSS was possible via image name on the agent details page

๐Ÿ“… Published: Dec. 20, 2024, 2:11 p.m. ๐Ÿ”„ Last Modified: Jan. 2, 2025, 6:49 p.m.

6.3

CVSS3.1

CVE-2024-56351 -

In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles

๐Ÿ“… Published: Dec. 20, 2024, 2:11 p.m. ๐Ÿ”„ Last Modified: Jan. 2, 2025, 6:49 p.m.

4.3

CVSS3.1

CVE-2024-56350 -

In JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projects

๐Ÿ“… Published: Dec. 20, 2024, 2:11 p.m. ๐Ÿ”„ Last Modified: Jan. 2, 2025, 6:50 p.m.
Total resulsts: 343942
Page 6876 of 34,395
ยซ previous page ยป next page
Filters