6.8

CVSS3.1

CVE-2024-54147 - Altair GraphQL Client's desktop app does not validate HTTPS certificates

Altair is a GraphQL client for all platforms. Prior to version 8.0.5, Altair GraphQL Client's desktop app does not validate HTTPS certificates allowing a man-in-the-middle to intercept all requests. Any Altair users on untrusted networks (eg. public wifi, malicious DNS servers) may have all GraphQL…

πŸ“… Published: Dec. 9, 2024, 6:55 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2024-53847 - Trix vulnerable to Cross-site Scripting on copy & paste

The Trix rich text editor, prior to versions 2.1.9 and 1.3.3, is vulnerable to cross-site scripting (XSS) + mutation XSS attacks when pasting malicious code. An attacker could trick a user to copy and paste malicious code that would execute arbitrary JavaScript code within the context of the user's…

πŸ“… Published: Dec. 9, 2024, 6:49 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-52599 - Tuleap vulnerable to XSS in the Gantt chart of the tracker plugin

Tuleap is an open source suite to improve management of software developments and collaboration. In Tuleap Community Edition prior to version 16.1.99.50 and Tuleap Enterprise Edition prior to versions 16.1-4 and 16.0-7, a malicious user with the ability to create an artifact in a tracker with a Gan…

πŸ“… Published: Dec. 9, 2024, 6:41 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 4:19 p.m.

5.4

CVSS3.1

CVE-2024-52586 - eLabFTW MFA bypass

eLabFTW is an open source electronic lab notebook for research labs. A vulnerability has been found starting in version 4.6.0 and prior to version 5.1.0 that allows an attacker to bypass eLabFTW's built-in multifactor authentication mechanism. An attacker who can authenticate locally (by knowing or…

πŸ“… Published: Dec. 9, 2024, 6:38 p.m. πŸ”„ Last Modified: Aug. 15, 2025, 6:43 p.m.

7.8

CVSS3.1

CVE-2024-11608 -

A maliciously crafted SKP file, when linked or imported into Autodesk Revit, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

πŸ“… Published: Dec. 9, 2024, 5:53 p.m. πŸ”„ Last Modified: Sept. 26, 2025, 5:51 p.m.

7.8

CVSS3.1

CVE-2024-11454 - Untrusted Search Path vulnerability in Autodesk Revit

A maliciously crafted DLL file, when placed in the same directory as an RVT file could be loaded by Autodesk Revit, and execute arbitrary code in the context of the current process due to an untrusted search patch being utilized.

πŸ“… Published: Dec. 9, 2024, 5:48 p.m. πŸ”„ Last Modified: Sept. 26, 2025, 5:48 p.m.

5.5

CVSS3.1

CVE-2024-11268 - PDF File Parsing Vulnerability in Autodesk Revit

A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a crash or could lead to an arbitrary memory leak.

πŸ“… Published: Dec. 9, 2024, 5:42 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 4:51 p.m.

4.3

CVSS3.1

CVE-2024-45760 -

Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper access control vulnerability. A remote low privileged user could potentially exploit this vulnerability via the HTTP GET method leading to unauthorized action with elevated privileges.

πŸ“… Published: Dec. 9, 2024, 4:17 p.m. πŸ”„ Last Modified: Feb. 4, 2025, 6:04 p.m.

5.4

CVSS3.1

CVE-2024-45761 -

Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper input validation vulnerability. A remote low-privileged malicious user could potentially exploit this vulnerability to load any web plugins or Java class leading to the possibility of altering the behavior of ce…

πŸ“… Published: Dec. 9, 2024, 4:12 p.m. πŸ”„ Last Modified: Feb. 4, 2025, 6:01 p.m.

4.4

CVSS3.1

CVE-2023-7298 - Out-of-Bounds Write Vulnerability in in Autodesk Desktop Software

A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

πŸ“… Published: Dec. 9, 2024, 3:09 p.m. πŸ”„ Last Modified: Aug. 18, 2025, 9:15 p.m.
Total resulsts: 346571
Page 7301 of 34,658
Β« previous page Β» next page
Filters