7.5

CVSS3.0

CVE-2024-37377 -

A heap-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to cause a denial of service.

πŸ“… Published: Dec. 11, 2024, 6:52 p.m. πŸ”„ Last Modified: July 2, 2025, 8:26 p.m.

8.6

CVSS4.0

CVE-2024-47537 - GHSL-2024-094: GStreamer has an OOB-write in isomp4/qtdemux.c

GStreamer is a library for constructing graphs of media-handling components. The program attempts to reallocate the memory pointed to by stream->samples to accommodate stream->n_samples + samples_count elements of type QtDemuxSample. The problem is that samples_count is read from the input file. An…

πŸ“… Published: Dec. 11, 2024, 6:51 p.m. πŸ”„ Last Modified: March 17, 2026, 3:52 p.m.

5.3

CVSS4.0

CVE-2024-12479 - cjbi wetech-cms TopicDao.java searchTopicByKeyword sql injection

A vulnerability was found in cjbi wetech-cms 1.0/1.1/1.2 and classified as critical. This issue affects the function searchTopicByKeyword of the file wetech-cms-master\wetech-core\src\main\java\tech\wetech\cms\dao\TopicDao.java. The manipulation of the argument keyword leads to sql injection. The a…

πŸ“… Published: Dec. 11, 2024, 6:31 p.m. πŸ”„ Last Modified: Dec. 13, 2024, 5:10 p.m.

8.8

CVSS3.1

CVE-2024-12382 -

Use after free in Translate in Google Chrome prior to 131.0.6778.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: Dec. 11, 2024, 5:52 p.m. πŸ”„ Last Modified: Dec. 17, 2024, 4:56 a.m.

8.8

CVSS3.1

CVE-2024-12381 -

Type Confusion in V8 in Google Chrome prior to 131.0.6778.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: Dec. 11, 2024, 5:52 p.m. πŸ”„ Last Modified: Dec. 17, 2024, 4:56 a.m.

9.3

CVSS4.0

CVE-2024-50339 - GLPI vulnerable to unauthenticated session hijacking

GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.17, an unauthenticated user can retrieve all the sessions IDs and use them to steal any valid session. Version 10.0.17 contains a patch for this issue.

πŸ“… Published: Dec. 11, 2024, 5:48 p.m. πŸ”„ Last Modified: Jan. 10, 2025, 6:48 p.m.

7.2

CVSS4.0

CVE-2024-48912 - GLPI vulnerable to authenticated insecure account deletion

GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.17, an authenticated user can use an application endpoint to delete any user account. Version 10.0.17 contains a patch for this issue.

πŸ“… Published: Dec. 11, 2024, 5:03 p.m. πŸ”„ Last Modified: Jan. 10, 2025, 7:37 p.m.

7.5

CVSS4.0

CVE-2024-47761 - GLPI vulnerable to account takeover via the password reset feature

GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.17, an administrator with access to the sent notifications contents can take control of an account with higher privileges. Version 10.0.17 contains a patch for this issue.

πŸ“… Published: Dec. 11, 2024, 5 p.m. πŸ”„ Last Modified: Jan. 23, 2025, 8:37 p.m.

7.5

CVSS4.0

CVE-2024-47760 - GLPI vulnerable to account takeover via API

GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.17, a technician with an access to the API can take control of an account with higher privileges. Version 10.0.17 contains a patch for this issue.

πŸ“… Published: Dec. 11, 2024, 4:56 p.m. πŸ”„ Last Modified: Jan. 23, 2025, 8:23 p.m.

7.8

CVSS3.1

CVE-2024-11598 -

Under specific circumstances, insecure permissions in Ivanti Application Control before version 2024.3 HF1, 2024.1 HF2, or 2023.3 HF3 allows a local authenticated attacker to achieve local privilege escalation.

πŸ“… Published: Dec. 11, 2024, 4:50 p.m. πŸ”„ Last Modified: Jan. 23, 2025, 8:12 p.m.
Total resulsts: 343194
Page 6924 of 34,320
Β« previous page Β» next page
Filters