9.8

CVSS3.1

CVE-2024-54984 -

An issue in Quectel BG96 BG96MAR02A08M1G allows attackers to bypass authentication via a crafted NAS message. NOTE: this is disputed by the supplier.

πŸ“… Published: Dec. 19, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-54790 -

A SQL Injection vulnerability was found in /index.php in PHPGurukul Pre-School Enrollment System v1.0, which allows remote attackers to execute arbitrary code via the visittime parameter.

πŸ“… Published: Dec. 19, 2024, midnight πŸ”„ Last Modified: March 27, 2025, 4:30 p.m.

7.5

CVSS3.1

CVE-2024-54663 -

An issue was discovered in the Webmail Classic UI in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Local File Inclusion (LFI) vulnerability exists in the /h/rest endpoint, allowing authenticated remote attackers to include and access sensitive files in the WebRoot directory. Exploitation requ…

πŸ“… Published: Dec. 19, 2024, midnight πŸ”„ Last Modified: June 11, 2025, 9:17 p.m.

6.5

CVSS3.1

CVE-2024-55603 - Insufficient session invalidation in Kanboard

Kanboard is project management software that focuses on the Kanban methodology. In affected versions sessions are still usable even though their lifetime has exceeded. Kanboard implements a cutom session handler (`app/Core/Session/SessionHandler.php`), to store the session data in a database. There…

πŸ“… Published: Dec. 18, 2024, 11:52 p.m. πŸ”„ Last Modified: March 12, 2025, 5:42 p.m.

5.2

CVSS3.1

CVE-2021-29827 - IBM InfoSphere Information Server clickjacking

IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against…

πŸ“… Published: Dec. 18, 2024, 11:44 p.m. πŸ”„ Last Modified: March 12, 2025, 5:43 p.m.

5.4

CVSS3.1

CVE-2021-20553 - IBM Sterling B2B Integrator Standard Edition cross-site scripting

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted sessio…

πŸ“… Published: Dec. 18, 2024, 11:39 p.m. πŸ”„ Last Modified: March 6, 2025, 7:02 p.m.

5.5

CVSS3.1

CVE-2023-21586 - Acrobat Reader | NULL Pointer Dereference (CWE-476)

Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a NULL Pointer Dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of t…

πŸ“… Published: Dec. 18, 2024, 11:32 p.m. πŸ”„ Last Modified: Feb. 6, 2025, 6:16 p.m.

7.8

CVSS3.1

CVE-2022-44518 - Acrobat Reader | Use After Free (CWE-416)

Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in th…

πŸ“… Published: Dec. 18, 2024, 11:28 p.m. πŸ”„ Last Modified: Feb. 6, 2025, 6:18 p.m.

5.5

CVSS3.1

CVE-2022-44517 - Acrobat Reader | Out-of-bounds Read (CWE-125)

Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage thi…

πŸ“… Published: Dec. 18, 2024, 11:28 p.m. πŸ”„ Last Modified: Jan. 10, 2025, 9:45 p.m.

5.5

CVSS3.1

CVE-2022-44519 - Acrobat Reader | Use After Free (CWE-416)

Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploit…

πŸ“… Published: Dec. 18, 2024, 11:28 p.m. πŸ”„ Last Modified: Feb. 6, 2025, 6:18 p.m.
Total resulsts: 347736
Page 7271 of 34,774
Β« previous page Β» next page
Filters