4.8

CVSS3.1

CVE-2024-37776 -

A cross-site scripting (XSS) vulnerability in Sunbird DCIM dcTrack v9.1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in some admin screens.

πŸ“… Published: Dec. 16, 2024, midnight πŸ”„ Last Modified: June 20, 2025, 6:16 p.m.

5.9

CVSS3.1

CVE-2024-56087 -

An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while querying Search Template Dashboard. These are executed, leading to Server-Side Template Injection.

πŸ“… Published: Dec. 16, 2024, midnight πŸ”„ Last Modified: April 17, 2025, 1:50 a.m.

9.8

CVSS3.1

CVE-2024-55557 -

ui/pref/ProxyPrefView.java in weasis-core in Weasis 4.5.1 has a hardcoded key for symmetric encryption of proxy credentials.

πŸ“… Published: Dec. 16, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2024-55104 -

Online Nurse Hiring System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component /admin/add-nurse.php via the gender and emailid parameters.

πŸ“… Published: Dec. 16, 2024, midnight πŸ”„ Last Modified: March 28, 2025, 4:31 p.m.

5.4

CVSS3.1

CVE-2024-55554 -

Intrexx Portal Server before 12.0.2 allows XSS via a user-defined portlet.

πŸ“… Published: Dec. 16, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-37775 -

Incorrect access control in Sunbird DCIM dcTrack v9.1.2 allows attackers to create or update a ticket with a location which bypasses an RBAC check.

πŸ“… Published: Dec. 16, 2024, midnight πŸ”„ Last Modified: June 20, 2025, 6:16 p.m.

8.1

CVSS3.1

CVE-2024-56083 -

Cognition Devin before 2024-12-12 provides write access to code by an attacker who discovers the https://vscode-randomly_generated_string.devinapps.com URL (aka the VSCode live share URL) for a specific "Use Devin's Machine" session. For example, this URL may be discovered if a customer posts a scr…

πŸ“… Published: Dec. 16, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-56112 -

CyberPanel (aka Cyber Panel) before f0cf648 allows XSS via token or username to plogical/phpmyadminsignin.php.

πŸ“… Published: Dec. 16, 2024, midnight πŸ”„ Last Modified: Sept. 5, 2025, 12:30 a.m.

7.5

CVSS3.1

CVE-2024-8798 - Bluetooth: classic: avdtp: missing buffer length check

No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client.c.

πŸ“… Published: Dec. 15, 2024, 11:23 p.m. πŸ”„ Last Modified: Sept. 17, 2025, 6:15 a.m.

8.6

CVSS3.1

CVE-2024-11858 - Radare2: command injection via pebble application files in radare2

A flaw was found in Radare2, which contains a command injection vulnerability caused by insufficient input validation when handling Pebble Application files. Maliciously crafted inputs can inject shell commands during command parsing, leading to unintended behavior during file processing​

πŸ“… Published: Dec. 15, 2024, 1:57 p.m. πŸ”„ Last Modified: Aug. 5, 2025, 5:56 p.m.
Total resulsts: 349182
Page 7460 of 34,919
Β« previous page Β» next page
Filters