7.5

CVSS3.1

CVE-2024-55470 -

Oqtane Framework 6.0.0 is vulnerable to Incorrect Access Control. By manipulating the entityid parameter, attackers can bypass passcode validation and successfully log into the application or access restricted data without proper authorization. The lack of server-side validation exacerbates the iss…

📅 Published: Dec. 20, 2024, midnight 🔄 Last Modified: Dec. 20, 2024, 6:15 p.m.

8.7

CVSS4.0

CVE-2024-12700 - Tibbo AggreGate Network Manager Unrestricted Upload of File with Dangerous Type

There is an unrestricted file upload vulnerability where it is possible for an authenticated user (low privileged) to upload an jsp shell and execute code with the privileges of user running the web server.

📅 Published: Dec. 19, 2024, 10:50 p.m. 🔄 Last Modified: Dec. 20, 2024, 5:38 p.m.

7.7

CVSS4.0

CVE-2024-56327 - Malicious plugin names, recipients, or identities can cause arbitrary binary execution in pyrage

pyrage is a set of Python bindings for the rage file encryption library (age in Rust). `pyrage` uses the Rust `age` crate for its underlying operations, and `age` is vulnerable to GHSA-4fg7-vxc8-qx5w. All details of GHSA-4fg7-vxc8-qx5w are relevant to `pyrage` for the versions specified in this adv…

📅 Published: Dec. 19, 2024, 10:24 p.m. 🔄 Last Modified: Dec. 20, 2024, 6:15 p.m.

4

CVSS3.1

CVE-2024-54009 -

Remote authentication bypass vulnerability in HPE Alletra Storage MP B10000 in versions prior to version 10.4.5 could be remotely exploited to allow disclosure of information.

📅 Published: Dec. 19, 2024, 10:19 p.m. 🔄 Last Modified: Dec. 20, 2024, 5:10 p.m.

8.5

CVSS4.0

CVE-2024-11364 - Rockwell Automation Third Party Vulnerability in Arena®

Another “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to access a variable prior to it being initialized. If exploited, a threat actor could leverage this vulnerability to exe…

📅 Published: Dec. 19, 2024, 9:04 p.m. 🔄 Last Modified: July 11, 2025, 8:03 p.m.

8.8

CVSS3.1

CVE-2024-12729 -

A post-auth code injection vulnerability in the User Portal allows authenticated users to execute code remotely in Sophos Firewall older than version 21.0 MR1 (21.0.1).

📅 Published: Dec. 19, 2024, 8:58 p.m. 🔄 Last Modified: Nov. 12, 2025, 7:08 p.m.

8.5

CVSS4.0

CVE-2024-12672 - Rockwell Automation Third Party Vulnerability in Arena®

A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimat…

📅 Published: Dec. 19, 2024, 8:58 p.m. 🔄 Last Modified: April 3, 2025, 4:36 p.m.

8.5

CVSS4.0

CVE-2024-12175 - Rockwell Automation Code Execution Vulnerability in Arena

Another “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code…

📅 Published: Dec. 19, 2024, 8:53 p.m. 🔄 Last Modified: March 13, 2025, 5:15 p.m.

9.8

CVSS3.1

CVE-2024-12728 -

A weak credentials vulnerability potentially allows privileged system access via SSH to Sophos Firewall older than version 20.0 MR3 (20.0.3).

📅 Published: Dec. 19, 2024, 8:48 p.m. 🔄 Last Modified: Nov. 12, 2025, 7:20 p.m.

8.5

CVSS4.0

CVE-2024-11157 - Rockwell Automation Third Party Vulnerability in Arena

A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimat…

📅 Published: Dec. 19, 2024, 8:48 p.m. 🔄 Last Modified: March 13, 2025, 4:15 p.m.
Total resulsts: 343984
Page 6887 of 34,399
« previous page » next page
Filters