8.5

CVSS4.0

CVE-2024-9508 - Horner Automation Cscape Out-of-bounds Read

Horner Automation Cscape contains a memory corruption vulnerability, which could allow an attacker to disclose information and execute arbitrary code.

๐Ÿ“… Published: Dec. 13, 2024, 12:49 a.m. ๐Ÿ”„ Last Modified: Dec. 13, 2024, 9:14 p.m.

5.3

CVSS3.1

CVE-2024-55918 -

An issue was discovered in the Graphics::ColorNames package before 3.2.0 for Perl. There is an ambiguity between modules and filenames that can lead to HTML injection by an attacker who can create a file in the current working directory.

๐Ÿ“… Published: Dec. 13, 2024, midnight ๐Ÿ”„ Last Modified: Dec. 17, 2024, 8:15 p.m.

9.8

CVSS3.1

CVE-2024-55956 -

In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.

๐Ÿ“… Published: Dec. 13, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 4, 2025, 4:37 p.m.

5.9

CVSS3.1

CVE-2024-12289 - Boundary Controller Incorrectly Handles HTTP Requests On Initialization Which May Lead to a Denial โ€ฆ

Boundary Community Edition and Boundary Enterprise (โ€œBoundaryโ€) incorrectly handle HTTP requests during the initialization of the Boundary controller, which may cause the Boundary server to terminate prematurely. Boundary is only vulnerable to this flaw during the initialization of the Boundary conโ€ฆ

๐Ÿ“… Published: Dec. 12, 2024, 10:42 p.m. ๐Ÿ”„ Last Modified: Dec. 29, 2025, 5:17 p.m.

7.1

CVSS3.1

CVE-2024-55888 - Content Security Policy appears to be missing in software and production setup

Hush Line is an open-source whistleblower management system. Starting in version 0.1.0 and prior to version 0.3.5, the productions server appeared to have been misconfigured and missed providing any content security policy or security headers. This could result in bypassing of cross-site scripting โ€ฆ

๐Ÿ“… Published: Dec. 12, 2024, 7:28 p.m. ๐Ÿ”„ Last Modified: Dec. 13, 2024, 3:40 p.m.

6.9

CVSS3.1

CVE-2024-55886 - OpenTelemetry Logs source may lack authentication with some custom plugins

OpenSearch Data Prepper is a component of the OpenSearch project that accepts, filters, transforms, enriches, and routes data at scale. A vulnerability exists in the OpenTelemetry Logs source in Data Prepper starting inversion 2.1.0 and prior to version 2.10.2 where some custom authentication plugiโ€ฆ

๐Ÿ“… Published: Dec. 12, 2024, 7:25 p.m. ๐Ÿ”„ Last Modified: Dec. 4, 2025, 6:08 p.m.

6.9

CVSS4.0

CVE-2024-55885 - Beego Vulnerable to Collision Hazards of MD5 in Cache Key Filenames

beego is an open-source web framework for the Go programming language. Versions of beego prior to 2.3.4 use MD5 as a hashing algorithm. MD5 is no longer considered secure against well-funded opponents due to its vulnerability to collision attacks. Version 2.3.4 replaces MD5 with SHA256.

๐Ÿ“… Published: Dec. 12, 2024, 7:23 p.m. ๐Ÿ”„ Last Modified: Aug. 1, 2025, 8:18 p.m.

6.8

CVSS3.1

CVE-2024-55878 - Cross-site Scripting vulnerability in SimpleXLSXEx::readXfs and SimpeXLSX::toHTMLEx

SimpleXLSX is software for parsing and retrieving data from Excel XLSx files. Starting in version 1.0.12 and prior to version 1.1.12, when calling the extended toHTMLEx method, it is possible to execute arbitrary JavaScript code. Version 1.1.12 fixes the issue. As a workaround, don't use direct pubโ€ฆ

๐Ÿ“… Published: Dec. 12, 2024, 7:20 p.m. ๐Ÿ”„ Last Modified: Dec. 13, 2024, 3:57 p.m.

9.1

CVSS3.1

CVE-2024-55879 - XWiki allows RCE from script right in configurable sections

XWiki Platform is a generic wiki platform. Starting in version 2.3 and prior to versions 15.10.9, 16.3.0, any user with script rights can perform arbitrary remote code execution by adding instances of `XWiki.ConfigurableClass` to any page. This compromises the confidentiality, integrity and availabโ€ฆ

๐Ÿ“… Published: Dec. 12, 2024, 7:17 p.m. ๐Ÿ”„ Last Modified: April 30, 2025, 4:01 p.m.

10

CVSS3.1

CVE-2024-55877 - XWiki allows remote code execution from account through macro descriptions and XWiki.XWikiSyntaxMacโ€ฆ

XWiki Platform is a generic wiki platform. Starting in version 9.7-rc-1 and prior to versions 15.10.11, 16.4.1, and 16.5.0, any user with an account can perform arbitrary remote code execution by adding instances of `XWiki.WikiMacroClass` to any page. This compromises the confidentiality, integrityโ€ฆ

๐Ÿ“… Published: Dec. 12, 2024, 7:13 p.m. ๐Ÿ”„ Last Modified: April 30, 2025, 4:02 p.m.
Total resulsts: 343879
Page 6966 of 34,388
ยซ previous page ยป next page
Filters