7.5

CVSS3.1

CVE-2024-42384 - Integer Overflow or Wraparound in Mongoose Web Server library

Integer Overflow or Wraparound vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.

πŸ“… Published: Nov. 18, 2024, 9:04 a.m. πŸ”„ Last Modified: Nov. 7, 2025, 4:15 p.m.

8.1

CVSS3.1

CVE-2024-41971 - WAGO: Arbitrary File Overwrite in Multiple Devices

A low privileged remote attacker can overwrite an arbitrary file on the filesystem leading to a DoS and data loss.

πŸ“… Published: Nov. 18, 2024, 9:04 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.7

CVSS3.1

CVE-2024-41970 - WAGO: Unauthorized Diagnostic Data Exposure in Multiple Devices

A low privileged remote attackerΒ may gain access to forbidden diagnostic data due to incorrect permission assignment for critical resources.

πŸ“… Published: Nov. 18, 2024, 9:04 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.2

CVSS3.1

CVE-2024-42383 - Use of Out-of-range Pointer Offset in Mongoose Web Server library

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows to write a NULL byte value beyond the memory space dedicated for the hostname field.

πŸ“… Published: Nov. 18, 2024, 9:04 a.m. πŸ”„ Last Modified: Nov. 19, 2024, 5:55 p.m.

8.8

CVSS3.1

CVE-2024-41969 - WAGO: CODESYS V3 Configuration Authentication Bypass in Multiple Devices

A low privileged remote attacker mayΒ modify the configuration of the CODESYS V3 service through a missing authentication vulnerability which could lead to full system access and/or DoS.

πŸ“… Published: Nov. 18, 2024, 9:04 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2024-41967 - WAGO: Boot Mode Manipulation in Multiple Devices

A low privileged remote attackerΒ may modify the boot mode configuration setup of the device, leading to modification of the firmware upgrade process or a denial-of-service attack.

πŸ“… Published: Nov. 18, 2024, 9:03 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-41968 - WAGO: Docker Settings Manipulation in Multiple Devices

A low privileged remote attacker may modify the docker settings setup of the device, leading to a limited DoS.

πŸ“… Published: Nov. 18, 2024, 9:03 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-41151 - Apache HertzBeat: RCE by notice template injection vulnerability

Deserialization of Untrusted Data vulnerability in Apache HertzBeat. This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat: before 1.6.1. Users are recommended to upgrade to version 1.6.1, which fixes the issue.

πŸ“… Published: Nov. 18, 2024, 8:45 a.m. πŸ”„ Last Modified: June 24, 2025, 4:29 p.m.

7.5

CVSS3.1

CVE-2024-45791 - Apache HertzBeat: Exposure sensitive token via http GET method with query string

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat: before 1.6.1. Users are recommended to upgrade to version 1.6.1, which fixes the issue.

πŸ“… Published: Nov. 18, 2024, 8:45 a.m. πŸ”„ Last Modified: June 24, 2025, 4:22 p.m.

8.8

CVSS3.1

CVE-2024-45505 - Apache HertzBeat: Exists Native Deser RCE and file writing vulnerabilities

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache HertzBeat (incubating). This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat (incubating): before 1.6.1. Users are recommended to upgrade to…

πŸ“… Published: Nov. 18, 2024, 8:44 a.m. πŸ”„ Last Modified: June 24, 2025, 4:23 p.m.
Total resulsts: 345161
Page 7435 of 34,517
Β« previous page Β» next page
Filters