6.5

CVSS3.1

CVE-2024-49071 - Windows Defender Information Disclosure Vulnerability

Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender allows an authorized attacker to disclose information over a network.

📅 Published: Dec. 12, 2024, 7:07 p.m. 🔄 Last Modified: May 13, 2025, 3:25 p.m.

9.3

CVSS3.1

CVE-2024-49147 - Microsoft Update Catalog Elevation of Privilege Vulnerability

Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webserver.

📅 Published: Dec. 12, 2024, 7:07 p.m. 🔄 Last Modified: May 13, 2025, 3:25 p.m.

5.4

CVSS3.1

CVE-2024-55876 - XWiki's scheduler in subwiki allows scheduling operations for any main wiki user

XWiki Platform is a generic wiki platform. Starting in version 1.2-milestone-2 and prior to versions 15.10.9 and 16.3.0, any user with an account on the main wiki could run scheduling operations on subwikis. To reproduce, as a user on the main wiki without any special right, view the document `Sche…

📅 Published: Dec. 12, 2024, 6:59 p.m. 🔄 Last Modified: April 30, 2025, 4:02 p.m.

9.8

CVSS3.1

CVE-2024-55875 - http4k has a potential XXE (XML External Entity Injection) vulnerability

http4k is a functional toolkit for Kotlin HTTP applications. Prior to version 5.41.0.0, there is a potential XXE (XML External Entity Injection) vulnerability when http4k handling malicious XML contents within requests, which might allow attackers to read local sensitive information on server, trig…

📅 Published: Dec. 12, 2024, 6:56 p.m. 🔄 Last Modified: Dec. 13, 2024, 3:15 p.m.

8.6

CVSS4.0

CVE-2024-55663 - XWiki Platform has an SQL injection in getdocuments.vm with sort parameter

XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 13.10.5 and 14.3-rc-1, in `getdocument.vm`; the ordering of the returned documents is defined from an unsanitized request parameter (request.sort) and can allow any user to inject HQL. Depending on …

📅 Published: Dec. 12, 2024, 6:53 p.m. 🔄 Last Modified: Jan. 10, 2025, 6:02 p.m.

7.5

CVSS3.1

CVE-2024-47238 -

Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.

📅 Published: Dec. 12, 2024, 5:38 p.m. 🔄 Last Modified: Feb. 4, 2025, 3:52 p.m.

10

CVSS3.1

CVE-2024-55662 - XWiki allows remote code execution through the extension sheet

XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-1 and prior to versions 15.10.9 and 16.3.0, on instances where `Extension Repository Application` is installed, any user can execute any code requiring `programming` rights on the server. This vulnerability has been fixed …

📅 Published: Dec. 12, 2024, 5:25 p.m. 🔄 Last Modified: April 30, 2025, 4:03 p.m.

6.5

CVSS3.1

CVE-2024-52901 - IBM InfoSphere Information Server denial of service

IBM InfoSphere Information Server 11.7 could allow an authenticated user to GUI to not load or stop working due to improper input validation.

📅 Published: Dec. 12, 2024, 4:06 p.m. 🔄 Last Modified: Jan. 7, 2025, 6:16 p.m.

0.0

CVE-2024-12573 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-24752 Reason: This candidate is a reservation duplicate of CVE-2025-24752. Notes: All CVE users should reference CVE-2025-24752 instead of this candidate. All references and descriptions in this candidate have been removed to preve…

📅 Published: Dec. 12, 2024, 3:02 p.m. 🔄 Last Modified: Aug. 15, 2025, 2:26 p.m.

7.1

CVSS4.0

CVE-2024-55633 - Apache Superset: SQLLab Improper readonly query validation allows unauthorized write access

Improper Authorization vulnerability in Apache Superset. On Postgres analytic databases an attacker with SQLLab access can craft a specially designed SQL DML statement that is Incorrectly identified as a read-only query, enabling its execution. Non postgres analytics database connections and postgr…

📅 Published: Dec. 12, 2024, 2:36 p.m. 🔄 Last Modified: Feb. 12, 2025, 10:15 a.m.
Total resulsts: 343919
Page 6971 of 34,392
« previous page » next page
Filters