5.9

CVSS3.1

CVE-2024-10716 -

Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an XSS issue with search.

πŸ“… Published: Dec. 5, 2024, 3:28 p.m. πŸ”„ Last Modified: July 13, 2025, 11:31 a.m.

7.5

CVSS3.1

CVE-2024-53856 - rPGP Panics on Malformed Untrusted Input

rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows an attacker to trigger rpgp crashes by providing crafted data. This vulnerability is fixed in 0.14.1.

πŸ“… Published: Dec. 5, 2024, 3:24 p.m. πŸ”„ Last Modified: July 12, 2025, 4:01 p.m.

7.5

CVSS3.1

CVE-2024-53857 - rPGP Potential Resource Exhaustion when handling Untrusted Messages

rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows attackers to trigger resource exhaustion vulnerabilities in rpgp by providing crafted messages. This affects general message parsing and decryption with symmetric keys.

πŸ“… Published: Dec. 5, 2024, 3:22 p.m. πŸ”„ Last Modified: Dec. 5, 2024, 4:34 p.m.

4.6

CVSS3.1

CVE-2024-12247 - Improper propagation of permission scheme updates across cluster nodes

Mattermost versions 9.7.x <= 9.7.5, 9.8.x <= 9.8.2 and 9.9.x <= 9.9.2 fail to properly propagate permission scheme updates across cluster nodes which allows a user to keep old permissions, even if the permission scheme has been updated.

πŸ“… Published: Dec. 5, 2024, 3:20 p.m. πŸ”„ Last Modified: Oct. 1, 2025, 6:21 p.m.

5.5

CVSS3.1

CVE-2024-54001 - Kanboard allows a persistent HTML injection site scripting in settings page date format

Kanboard is project management software that focuses on the Kanban methodology. HTML can be injected and stored into the application settings section. The fields application_language, application_date_format,application_timezone and application_time_format allow arbirary user input which is reflect…

πŸ“… Published: Dec. 5, 2024, 3:17 p.m. πŸ”„ Last Modified: Dec. 5, 2024, 4:41 p.m.

9.2

CVSS4.0

CVE-2024-54129 - Improper Initialization of `imc` Scheme Leading to `SIGABRT` in ION-DTN BPv7

The NASA’s Interplanetary Overlay Network (ION) is an implementation of Delay/Disruption Tolerant Networking (DTN). A vulnerability exists in the version ION-DTN BPv7 implementation version 4.1.3 when receiving a bundle with an improper reference to the imc scheme with valid Service-Specific Part (…

πŸ“… Published: Dec. 5, 2024, 3:13 p.m. πŸ”„ Last Modified: Dec. 9, 2024, 8:30 p.m.

9.2

CVSS4.0

CVE-2024-54130 - Segmentation Fault in `forwardBundle` Function of ION-DTN BPv7 When Destination EID is `dtn:none` (…

The NASA’s Interplanetary Overlay Network (ION) is an implementation of Delay/Disruption Tolerant Networking (DTN). A segmentation fault occurs with ION-DTN BPv7 software version 4.1.3 when a bundle with a Destination Endpoint ID (EID) set to dtn:none is received. This causes the node to become unr…

πŸ“… Published: Dec. 5, 2024, 3:10 p.m. πŸ”„ Last Modified: Dec. 5, 2024, 5:24 p.m.

0.0

CVE-2024-12246 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: Dec. 5, 2024, 3:01 p.m. πŸ”„ Last Modified: Feb. 11, 2025, 2:15 a.m.

5.9

CVSS3.1

CVE-2024-11942 - Drupal core - Moderately critical - Improper error handling - SA-CORE-2024-002

A vulnerability in Drupal Core allows File Manipulation.This issue affects Drupal Core: from 10.0.0 before 10.2.10.

πŸ“… Published: Dec. 5, 2024, 2:42 p.m. πŸ”„ Last Modified: June 2, 2025, 4:20 p.m.

7.5

CVSS3.1

CVE-2024-11941 - Drupal core - Moderately critical - Denial of Service - SA-CORE-2024-001

A vulnerability in Drupal Core allows Excessive Allocation.This issue affects Drupal Core: from 10.2.0 before 10.2.2, from 10.1.0 before 10.1.8.

πŸ“… Published: Dec. 5, 2024, 2:39 p.m. πŸ”„ Last Modified: June 2, 2025, 4:18 p.m.
Total resulsts: 342375
Page 6932 of 34,238
Β« previous page Β» next page
Filters