9.8

CVSS3.1

CVE-2024-55586 -

Nette Database through 3.2.4 allows SQL injection in certain situations involving an untrusted filter that is directly passed to the where method. NOTE: the vendor's position is that this is intended behavior.

πŸ“… Published: Dec. 10, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-54751 -

COMFAST CF-WR630AX v2.7.0.2 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

πŸ“… Published: Dec. 10, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8

CVSS3.1

CVE-2024-50699 -

TP-Link TL-WR845N(UN)_V4_201214, TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 were discovered to contain weak default credentials for the Administrator account.

πŸ“… Published: Dec. 10, 2024, midnight πŸ”„ Last Modified: July 2, 2025, 8:28 p.m.

6.5

CVSS3.1

CVE-2024-50928 -

Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to change the wakeup interval of end devices in controller memory, disrupting the device's communications with the controller.

πŸ“… Published: Dec. 10, 2024, midnight πŸ”„ Last Modified: July 1, 2025, 3:32 p.m.

9.8

CVSS3.1

CVE-2024-46442 -

An issue in the BYD Dilink Headunit System v3.0 to v4.0 allows attackers to bypass authentication via a bruteforce attack.

πŸ“… Published: Dec. 10, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.2

CVSS3.1

CVE-2024-50929 -

Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to arbitrarily change the device type in the controller's memory, leading to a Denial of Service (DoS).

πŸ“… Published: Dec. 10, 2024, midnight πŸ”„ Last Modified: July 1, 2025, 3:32 p.m.

5.5

CVSS3.1

CVE-2024-46657 -

Artifex Software mupdf v1.24.9 was discovered to contain a segmentation fault via the component /tools/pdfextract.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.

πŸ“… Published: Dec. 10, 2024, midnight πŸ”„ Last Modified: July 1, 2025, 1:39 p.m.

4.4

CVSS3.1

CVE-2024-55550 -

Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to the admin access lev…

πŸ“… Published: Dec. 10, 2024, midnight πŸ”„ Last Modified: Nov. 4, 2025, 3:02 p.m.

9.8

CVSS3.1

CVE-2024-53552 -

CrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover.

πŸ“… Published: Dec. 10, 2024, midnight πŸ”„ Last Modified: June 27, 2025, 5:58 p.m.

7.5

CVSS3.1

CVE-2024-51165 -

SQL injection vulnerability in JEPAAS7.2.8, via /je/rbac/rbac/loadLoginCount in the dateVal parameter, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.

πŸ“… Published: Dec. 10, 2024, midnight πŸ”„ Last Modified: June 24, 2025, 12:37 a.m.
Total resulsts: 346578
Page 7299 of 34,658
Β« previous page Β» next page
Filters