4

CVSS3.1

CVE-2024-54009 -

Remote authentication bypass vulnerability in HPE Alletra Storage MP B10000 in versions prior to version 10.4.5 could be remotely exploited to allow disclosure of information.

📅 Published: Dec. 19, 2024, 10:19 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2024-11364 - Rockwell Automation Third Party Vulnerability in Arena®

Another “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to access a variable prior to it being initialized. If exploited, a threat actor could leverage this vulnerability to exe…

📅 Published: Dec. 19, 2024, 9:04 p.m. 🔄 Last Modified: July 11, 2025, 8:03 p.m.

8.8

CVSS3.1

CVE-2024-12729 -

A post-auth code injection vulnerability in the User Portal allows authenticated users to execute code remotely in Sophos Firewall older than version 21.0 MR1 (21.0.1).

📅 Published: Dec. 19, 2024, 8:58 p.m. 🔄 Last Modified: Nov. 12, 2025, 7:08 p.m.

8.5

CVSS4.0

CVE-2024-12672 - Rockwell Automation Third Party Vulnerability in Arena®

A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimat…

📅 Published: Dec. 19, 2024, 8:58 p.m. 🔄 Last Modified: April 3, 2025, 4:36 p.m.

8.5

CVSS4.0

CVE-2024-12175 - Rockwell Automation Code Execution Vulnerability in Arena

Another “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code…

📅 Published: Dec. 19, 2024, 8:53 p.m. 🔄 Last Modified: March 13, 2025, 5:15 p.m.

9.8

CVSS3.1

CVE-2024-12728 -

A weak credentials vulnerability potentially allows privileged system access via SSH to Sophos Firewall older than version 20.0 MR3 (20.0.3).

📅 Published: Dec. 19, 2024, 8:48 p.m. 🔄 Last Modified: Nov. 12, 2025, 7:20 p.m.

8.5

CVSS4.0

CVE-2024-11157 - Rockwell Automation Third Party Vulnerability in Arena

A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimat…

📅 Published: Dec. 19, 2024, 8:48 p.m. 🔄 Last Modified: March 13, 2025, 4:15 p.m.

9.8

CVSS3.1

CVE-2024-12727 -

A pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall versions older than 21.0 MR1 (21.0.1) allows access to the reporting database and can lead to remote code execution if a specific configuration of Secure PDF eXchange (SPX) is enabled in combination with the f…

📅 Published: Dec. 19, 2024, 8:26 p.m. 🔄 Last Modified: Nov. 12, 2025, 7:27 p.m.

8

CVSS3.1

CVE-2024-12111 - Potential LDAP injection vulnerability in OpenText Privileged Access Manager

In a specific scenario a LDAP user can abuse the authentication process using injection attack in OpenText Privileged Access Manager that allows authentication bypass. This issue affects Privileged Access Manager version 23.3(4.4); 24.3(4.5)

📅 Published: Dec. 19, 2024, 8:10 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-7139 - Denial of Service in Silicon Labs RS9116 Bluetooth SDK

Due to an unchecked buffer length, a specially crafted L2CAP packet can cause a buffer overflow. This buffer overflow triggers an assert, which results in a temporary denial of service.  If a watchdog timer is not enabled, a hard reset is required to recover the device.

📅 Published: Dec. 19, 2024, 7:24 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 7407 of 34,919
« previous page » next page
Filters