9.8

CVSS3.1

CVE-2024-55956 -

In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.

📅 Published: Dec. 13, 2024, midnight 🔄 Last Modified: Nov. 4, 2025, 4:37 p.m.

5.9

CVSS3.1

CVE-2024-12289 - Boundary Controller Incorrectly Handles HTTP Requests On Initialization Which May Lead to a Denial …

Boundary Community Edition and Boundary Enterprise (“Boundary”) incorrectly handle HTTP requests during the initialization of the Boundary controller, which may cause the Boundary server to terminate prematurely. Boundary is only vulnerable to this flaw during the initialization of the Boundary con…

📅 Published: Dec. 12, 2024, 10:42 p.m. 🔄 Last Modified: Dec. 29, 2025, 5:17 p.m.

7.1

CVSS3.1

CVE-2024-55888 - Content Security Policy appears to be missing in software and production setup

Hush Line is an open-source whistleblower management system. Starting in version 0.1.0 and prior to version 0.3.5, the productions server appeared to have been misconfigured and missed providing any content security policy or security headers. This could result in bypassing of cross-site scripting …

📅 Published: Dec. 12, 2024, 7:28 p.m. 🔄 Last Modified: Dec. 13, 2024, 3:40 p.m.

6.9

CVSS3.1

CVE-2024-55886 - OpenTelemetry Logs source may lack authentication with some custom plugins

OpenSearch Data Prepper is a component of the OpenSearch project that accepts, filters, transforms, enriches, and routes data at scale. A vulnerability exists in the OpenTelemetry Logs source in Data Prepper starting inversion 2.1.0 and prior to version 2.10.2 where some custom authentication plugi…

📅 Published: Dec. 12, 2024, 7:25 p.m. 🔄 Last Modified: Dec. 4, 2025, 6:08 p.m.

6.9

CVSS4.0

CVE-2024-55885 - Beego Vulnerable to Collision Hazards of MD5 in Cache Key Filenames

beego is an open-source web framework for the Go programming language. Versions of beego prior to 2.3.4 use MD5 as a hashing algorithm. MD5 is no longer considered secure against well-funded opponents due to its vulnerability to collision attacks. Version 2.3.4 replaces MD5 with SHA256.

📅 Published: Dec. 12, 2024, 7:23 p.m. 🔄 Last Modified: Aug. 1, 2025, 8:18 p.m.

6.8

CVSS3.1

CVE-2024-55878 - Cross-site Scripting vulnerability in SimpleXLSXEx::readXfs and SimpeXLSX::toHTMLEx

SimpleXLSX is software for parsing and retrieving data from Excel XLSx files. Starting in version 1.0.12 and prior to version 1.1.12, when calling the extended toHTMLEx method, it is possible to execute arbitrary JavaScript code. Version 1.1.12 fixes the issue. As a workaround, don't use direct pub…

📅 Published: Dec. 12, 2024, 7:20 p.m. 🔄 Last Modified: Dec. 13, 2024, 3:57 p.m.

9.1

CVSS3.1

CVE-2024-55879 - XWiki allows RCE from script right in configurable sections

XWiki Platform is a generic wiki platform. Starting in version 2.3 and prior to versions 15.10.9, 16.3.0, any user with script rights can perform arbitrary remote code execution by adding instances of `XWiki.ConfigurableClass` to any page. This compromises the confidentiality, integrity and availab…

📅 Published: Dec. 12, 2024, 7:17 p.m. 🔄 Last Modified: April 30, 2025, 4:01 p.m.

10

CVSS3.1

CVE-2024-55877 - XWiki allows remote code execution from account through macro descriptions and XWiki.XWikiSyntaxMac…

XWiki Platform is a generic wiki platform. Starting in version 9.7-rc-1 and prior to versions 15.10.11, 16.4.1, and 16.5.0, any user with an account can perform arbitrary remote code execution by adding instances of `XWiki.WikiMacroClass` to any page. This compromises the confidentiality, integrity…

📅 Published: Dec. 12, 2024, 7:13 p.m. 🔄 Last Modified: April 30, 2025, 4:02 p.m.

6.5

CVSS3.1

CVE-2024-49071 - Windows Defender Information Disclosure Vulnerability

Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender allows an authorized attacker to disclose information over a network.

📅 Published: Dec. 12, 2024, 7:07 p.m. 🔄 Last Modified: May 13, 2025, 3:25 p.m.

9.3

CVSS3.1

CVE-2024-49147 - Microsoft Update Catalog Elevation of Privilege Vulnerability

Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webserver.

📅 Published: Dec. 12, 2024, 7:07 p.m. 🔄 Last Modified: May 13, 2025, 3:25 p.m.
Total resulsts: 343887
Page 6967 of 34,389
« previous page » next page
Filters